PT-2009-2779 · Microsoft · Windows Server 2003+2
Cesar Cerrudo
·
Published
2009-04-15
·
Updated
2019-02-26
·
CVE-2009-0079
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows XP versions SP2 through SP3
Microsoft Windows Server 2003 versions SP1 through SP2
Description
The issue arises from the RPCSS service in Microsoft Windows not properly isolating processes running under the NetworkService or LocalService accounts. This allows local users to gain privileges by accessing the resources of one of the processes. An attacker could exploit this to run code with elevated privileges, potentially executing arbitrary code and taking complete control of the affected system. This could enable the attacker to install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations
For Microsoft Windows XP versions SP2 through SP3, update to a version that includes the fix for this issue.
For Microsoft Windows Server 2003 versions SP1 through SP2, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the RPCSS service to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows Server 2003
Windows Xp
Windows