7.2
CVE-2009-1126
- EPSS 1.43%
- Veröffentlicht 10.06.2009 18:30:00
- Zuletzt bearbeitet 16.06.2026 23:06:33
- Erkennungen
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly validate the user-mode input associated with the editing of an unspecified desktop parameter, which allows local users to gain privileges via a crafted application, aka "Windows Desktop Parameter Edit Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2000 Update sp4
Microsoft ≫ Windows Server 2003 Update sp2
Microsoft ≫ Windows Server 2008 Edition x32
Microsoft ≫ Windows Server 2008 Edition x64
Microsoft ≫ Windows Server 2008 Update sp2 Edition itanium
Microsoft ≫ Windows Server 2008 Version sp2 Update x32
Microsoft ≫ Windows Server 2008 Version sp2 Update x64
Microsoft ≫ Windows Vista Edition x64
Microsoft ≫ Windows Vista Update sp1
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows Xp Update sp2
Microsoft ≫ Windows Xp Update sp3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.43% | 0.703 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://www.us-cert.gov/cas/techalerts/TA09-160A.html
http://secunia.com/advisories/35372
http://www.securitytracker.com/id?1022359
http://www.vupen.com/english/advisories/2009/1544
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-025
http://osvdb.org/54943
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6016