6.9

CVE-2009-1922

The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel mode, which allows local users to gain privileges via a crafted request, aka "MSMQ Null Pointer Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2000 Version - Update sp4
Microsoft ≫ Windows Vista Version - Update - Edition x64
Microsoft ≫ Windows Xp Version - Update sp2
Microsoft ≫ Windows Xp Version - Update sp2 Edition x64
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.35% 0.677
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.us-cert.gov/cas/techalerts/TA09-223A.html
US Government Resource
http://en.securitylab.ru/lab/PT-2008-09
http://osvdb.org/56901
http://secunia.com/advisories/36214
Vendor Advisory
http://www.securityfocus.com/archive/1/505691/100/0/threaded
http://www.securitytracker.com/id?1022714
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-040
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6109