PT-2010-3518 · Microsoft · Windows Xp+2
Matthieu Suiche
·
Published
2010-08-11
·
Updated
2019-02-26
·
CVE-2010-1895
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows XP versions SP2 through SP3
Microsoft Windows Server 2003 version SP2
Description
The issue arises from improper memory allocation by Windows kernel-mode drivers when copying data from user mode to kernel mode. This allows local users to potentially gain privileges through a crafted application. An attacker who successfully exploits this could run arbitrary code in kernel mode, enabling them to install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations
For Microsoft Windows XP versions SP2 through SP3, update to a version that properly allocates memory when copying from user mode to prevent exploitation.
For Microsoft Windows Server 2003 version SP2, apply the necessary patch to fix the memory allocation issue in kernel-mode drivers.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows Server 2003
Windows Xp