PT-2006-4104 · Microsoft · Windows Xp
Daniel Hckmann
+1
·
Published
2006-06-24
·
Updated
2024-08-07
·
CVE-2006-3209
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows XP
Description
The Task scheduler (at.exe) on Microsoft Windows XP spawns each scheduled process with SYSTEM permissions, which allows local users to gain privileges. Note that this issue has been disputed by third parties, who state that the Task scheduler is limited to the Administrators group by default upon installation.
Recommendations
For Microsoft Windows XP, consider restricting access to the Task scheduler to minimize the risk of exploitation. As a temporary workaround, limit the privileges of scheduled processes to prevent local users from gaining elevated permissions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows Xp