Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalService accounts, which might allow context-dependent attackers to gain privileges by using one service process to capture a resource from a second service process that has a LocalSystem privilege-escalation ability, related to improper management of the SeImpersonatePrivilege user right, as originally reported for Internet Information Services (IIS), aka Token Kidnapping.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2008-04-21 10:05
Updated : 2019-02-26 06:04
NVD link : CVE-2008-1436
Mitre link : CVE-2008-1436
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
microsoft
- windows_vista
- windows_xp
- windows_server_2008
- windows-nt
- windows_server_2003