PT-2012-2376 · Microsoft · Windows Vista+4
Published
2012-05-08
·
Updated
2023-12-07
·
CVE-2012-0178
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Windows Partition Manager versions in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1
Description
The issue is related to an elevation of privilege vulnerability in the way Windows Partition Manager handles device relations requests. This could allow an attacker to run arbitrary code in kernel mode, enabling them to install programs, view, change, or delete data, or create new accounts with full administrative rights. The vulnerability can be exploited by making multiple simultaneous Plug and Play (PnP) Configuration Manager function calls via a crafted application.
Recommendations
For Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows 7
Windows Partition Manager
Windows Server 2008
Windows Vista