PT-2010-5181 · Microsoft · Windows Vista+5

Published

2010-12-16

·

Updated

2023-12-07

·

CVE-2010-3943

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows XP versions SP2 through SP3 Windows Server 2003 version SP2 Windows Vista versions SP1 through SP2 Windows Server 2008 versions Gold through SP2 and R2 Windows 7 (affected versions not specified)
Description The issue is related to the management of kernel-mode driver objects by Windows Kernel-mode drivers, which can lead to elevation of privilege. This could allow an attacker to run arbitrary code in kernel mode, enabling them to install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations For Windows XP versions SP2 through SP3, update to a version that includes the fix for this issue. For Windows Server 2003 version SP2, apply the necessary patch to resolve the vulnerability. For Windows Vista versions SP1 through SP2, install the update that addresses this issue. For Windows Server 2008 versions Gold through SP2 and R2, apply the relevant security update to fix the vulnerability. For Windows 7, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2010-3943

Affected Products

Windows
Windows 7
Windows Server 2003
Windows Server 2008
Windows Vista
Windows Xp