PT-2010-5181 · Microsoft · Windows Vista+5
Published
2010-12-16
·
Updated
2023-12-07
·
CVE-2010-3943
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Windows XP versions SP2 through SP3
Windows Server 2003 version SP2
Windows Vista versions SP1 through SP2
Windows Server 2008 versions Gold through SP2 and R2
Windows 7 (affected versions not specified)
Description
The issue is related to the management of kernel-mode driver objects by Windows Kernel-mode drivers, which can lead to elevation of privilege. This could allow an attacker to run arbitrary code in kernel mode, enabling them to install programs, view, change, or delete data, or create new accounts with full user rights.
Recommendations
For Windows XP versions SP2 through SP3, update to a version that includes the fix for this issue.
For Windows Server 2003 version SP2, apply the necessary patch to resolve the vulnerability.
For Windows Vista versions SP1 through SP2, install the update that addresses this issue.
For Windows Server 2008 versions Gold through SP2 and R2, apply the relevant security update to fix the vulnerability.
For Windows 7, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows 7
Windows Server 2003
Windows Server 2008
Windows Vista
Windows Xp