PT-2009-2779 · Microsoft · Windows Server 2003+2

Cesar Cerrudo

·

Published

2009-04-15

·

Updated

2019-02-26

·

CVE-2009-0079

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows XP versions SP2 through SP3 Microsoft Windows Server 2003 versions SP1 through SP2
Description The issue arises from the RPCSS service in Microsoft Windows not properly isolating processes running under the NetworkService or LocalService accounts. This allows local users to gain privileges by accessing the resources of one of the processes. An attacker could exploit this to run code with elevated privileges, potentially executing arbitrary code and taking complete control of the affected system. This could enable the attacker to install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations For Microsoft Windows XP versions SP2 through SP3, update to a version that includes the fix for this issue. For Microsoft Windows Server 2003 versions SP1 through SP2, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the RPCSS service to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0079

Affected Products

Windows Server 2003
Windows Xp
Windows