The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows local administrators to bypass unspecified "security software" and gain privileges via a crafted call that triggers an overwrite of an arbitrary memory location. NOTE: the vendor disputes the significance of this report, stating that 'the Administrator to SYSTEM "escalation" is not a security boundary we defend.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T05:59:56.236Z
Reserved: 2009-08-03T00:00:00
Link: CVE-2009-2653
No data.
Status : Deferred
Published: 2009-08-03T14:30:00.687
Modified: 2025-04-09T00:30:58.490
Link: CVE-2009-2653
No data.
OpenCVE Enrichment
No data.
Weaknesses