[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244625

 
 

909

 
 

193379

 
 

277

Paid content will be excluded from the download.


Download | Alert*
OVAL

Elevation of privilege vulnerability in the Microsoft Windows Client/Server Run-time Subsystem (CSRSS) in Windows XP and Windows Server 2003 - MS11-010

ID: oval:org.secpod.oval:def:1035Date: (C)2011-05-23   (M)2022-09-09
Class: PATCHFamily: windows




The host is missing an Important security update according to Microsoft security bulletin, MS11-010. The update is required to fix elevation of privilege vulnerability in Windows Client/Server Run-time Subsystem (CSRSS) in Windows XP and Windows Server 2003. A flaw is present in CSRSS, which fails to handle a specially crafted application that continues to run even after log off. Successful exploitation could allow attackers to obtain elevated privileges by starting the application and acquire the logon credentials of subsequent users. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.

Platform:
Microsoft Windows Server 2003
Microsoft Windows XP
Product:
Windows Client/Server Run-time Subsystem
Reference:
MS11-010
CVE-2011-0030
CVE    1
CVE-2011-0030
CPE    8
cpe:/o:microsoft:windows_xp
cpe:/o:microsoft:windows_xp::sp3
cpe:/o:microsoft:windows_xp:::x86
cpe:/o:microsoft:windows_2003_server::sp2
...
XCCDF    3
xccdf_com.secpod_benchmark_microsoft-windows-server-2003
xccdf_com.secpod_benchmark_microsoft-windows-xp
xccdf_scaprepo.com_benchmark_microsoft-windows-server-2003

© SecPod Technologies