6.9
CVE-2009-0080
- EPSS 2.36%
- Veröffentlicht 15.04.2009 08:00:00
- Zuletzt bearbeitet 16.06.2026 23:04:13
- Erkennungen
The ThreadPool class in Windows Vista Gold and SP1, and Server 2008, does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by leveraging incorrect thread ACLs to access the resources of one of the processes, aka "Windows Thread Pool ACL Weakness Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows Server 2008 Version -
Microsoft ≫ Windows Vista Version -
Microsoft ≫ Windows Vista Version - HwPlatform x64
Microsoft ≫ Windows Vista Version - Update sp1
Microsoft ≫ Windows Vista Version - Update sp1 HwPlatform x64
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.36% | 0.815 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.9 | 3.4 | 10 |
AV:L/AC:M/Au:N/C:C/I:C/A:C
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
http://www.us-cert.gov/cas/techalerts/TA09-104A.html
http://www.vupen.com/english/advisories/2009/1026
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-012
http://www.securitytracker.com/id?1022044
http://osvdb.org/53668
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6177