The ThreadPool class in Windows Vista Gold and SP1, and Server 2008, does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, which allows local users to gain privileges by leveraging incorrect thread ACLs to access the resources of one of the processes, aka "Windows Thread Pool ACL Weakness Vulnerability."
References
Link | Resource |
---|---|
http://osvdb.org/53668 | Broken Link |
http://www.securitytracker.com/id?1022044 | Third Party Advisory VDB Entry |
http://www.us-cert.gov/cas/techalerts/TA09-104A.html | Third Party Advisory US Government Resource |
http://www.vupen.com/english/advisories/2009/1026 | Permissions Required |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-012 | Patch Vendor Advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6177 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
08 Nov 2021, 21:45
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:microsoft:windows_server:2008:-:x64:*:*:*:*:* cpe:2.3:o:microsoft:windows_vista:*:sp1:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_vista:*:sp1:x64:*:*:*:*:* cpe:2.3:o:microsoft:windows_server:2008:-:itanium:*:*:*:*:* cpe:2.3:o:microsoft:windows_vista:*:*:x64:*:*:*:*:* |
cpe:2.3:o:microsoft:windows_vista:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2008:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_vista:-:sp1:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_vista:-:sp1:*:*:*:*:x64:* cpe:2.3:o:microsoft:windows_vista:-:*:*:*:*:*:x64:* |
References | (CERT) http://www.us-cert.gov/cas/techalerts/TA09-104A.html - Third Party Advisory, US Government Resource | |
References | (VUPEN) http://www.vupen.com/english/advisories/2009/1026 - Permissions Required | |
References | (OVAL) https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6177 - Third Party Advisory | |
References | (MS) https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-012 - Patch, Vendor Advisory | |
References | (OSVDB) http://osvdb.org/53668 - Broken Link | |
References | (SECTRACK) http://www.securitytracker.com/id?1022044 - Third Party Advisory, VDB Entry | |
CWE | CWE-269 |
Information
Published : 2009-04-15 08:00
Updated : 2024-02-04 17:33
NVD link : CVE-2009-0080
Mitre link : CVE-2009-0080
CVE.ORG link : CVE-2009-0080
JSON object : View
Products Affected
microsoft
- windows_vista
- windows_server_2008
CWE
CWE-269
Improper Privilege Management