PT-2012-2376 · Microsoft · Windows Vista+4

Published

2012-05-08

·

Updated

2023-12-07

·

CVE-2012-0178

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows Partition Manager versions in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1
Description The issue is related to an elevation of privilege vulnerability in the way Windows Partition Manager handles device relations requests. This could allow an attacker to run arbitrary code in kernel mode, enabling them to install programs, view, change, or delete data, or create new accounts with full administrative rights. The vulnerability can be exploited by making multiple simultaneous Plug and Play (PnP) Configuration Manager function calls via a crafted application.
Recommendations For Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2012-0178

Affected Products

Windows
Windows 7
Windows Partition Manager
Windows Server 2008
Windows Vista