Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Daniel Hckmann

Researcher fromPandora Security
#38453of 53,630
7.2Total CVSS
Vulnerabilities · 1
PT-2006-4104
7.2
2006-06-24
Microsoft · Windows Xp · CVE-2006-3209
**Name of the Vulnerable Software and Affected Versions** Microsoft Windows XP **Description** The Task scheduler (at.exe) on Microsoft Windows XP spawns each scheduled process with SYSTEM permissions, which allows local users to gain privileges. Note that this issue has been disputed by third parties, who state that the Task scheduler is limited to the Administrators group by default upon installation. **Recommendations** For Microsoft Windows XP, consider restricting access to the Task scheduler to minimize the risk of exploitation. As a temporary workaround, limit the privileges of scheduled processes to prevent local users from gaining elevated permissions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.