PT-2007-2286 · Microsoft · Windows

Published

2007-02-23

·

Updated

2021-08-09

·

CVE-2007-0843

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Microsoft Windows versions 2000 through Vista
Description: The issue concerns the ReadDirectoryChangesW API function, which does not properly check permissions for child objects. This allows local users to bypass permissions by opening a directory with LIST (READ) access and using the ReadDirectoryChangesW function to monitor changes to files without LIST permissions. As a result, sensitive information such as filenames and access times can be determined.
Recommendations: For Microsoft Windows versions 2000 through Vista, consider restricting access to the ReadDirectoryChangesW API function until a patch is available. As a temporary workaround, limit directory access to only necessary users and groups to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-0843

Affected Products

Windows