Информационная безопасность
[RU] switch to
English Version



CVECVE-2007-1209
СтатусCandidate
ОписаниеUse-after-free vulnerability in the Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Vista does not properly handle connection resources when starting and stopping processes, which allows local users to gain privileges by opening and closing multiple ApiPort connections, which leaves a "dangling pointer" to a process data structure.
ВажностьMedium
CVSS score5,6
CVSS vector(AV:L/AC:H/Au:NR/C:C/I:C/A:C/B:N)
PhaseAssigned (02.03.2007)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-1209
ReferencesBID : 23338
 BUGTRAQ : 20070410 EEYE: Windows Vista CSRSS Dangling Process Pointer Privilege Escalation
 CERT-VN : VU#219848
 CERT : TA07-100A
 FRSIRT : ADV-2007-1325
 HP : HPSBST02208
 HP : SSRT071365
 MISC : http://research.eeye.com/html/advisories/published...
 MS : MS07-021
 OSVDB : 34008
 SECTRACK : 1017897
 SECUNIA : 24823
SecurityVulns:Повреждение памяти в Microsoft Windows (memory corruption)

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server