[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Microsoft Windows Tracing Feature for Services privilege escalation vulnerability - MS10-059

ID: oval:org.secpod.oval:def:1725Date: (C)2011-08-05   (M)2023-12-14
Class: PATCHFamily: windows




The host is missing a critical security update according to Microsoft security bulletin, MS10-059. The update is required to fix privilege escalation vulnerability. A flaw is present in the Tracing Feature for Services in Microsoft Windows, which fails to process specially crafted long strings from the registry and to access control lists (ACLs) on the registry keys. Successful exploitation could allow an attacker to gain privileges via vectors involving a named pipe and impersonation.

Platform:
Microsoft Windows Vista
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows 7
Reference:
MS10-059
CVE-2010-2554
CVE-2010-2555
CVE    2
CVE-2010-2554
CVE-2010-2555
CPE    23
cpe:/o:microsoft:windows_server_2008:::x64
cpe:/o:microsoft:windows_server_2008:::x86
cpe:/o:microsoft:windows_7:::x64
cpe:/o:microsoft:windows_7:::x86
...
XCCDF    5
xccdf_com.secpod_benchmark_microsoft-windows-server-2008
xccdf_scaprepo.com_benchmark_microsoft-windows-server-2008-r2
xccdf_com.secpod_benchmark_microsoft-windows-7
xccdf_com.secpod_benchmark_microsoft-windows-server-2008-r2
...

© SecPod Technologies