Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2009-1922 | First vendor Publication | 2009-08-12 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 6.9 | Attack Range | Local |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 3.4 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel mode, which allows local users to gain privileges via a crafted request, aka "MSMQ Null Pointer Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1922 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-264 | Permissions, Privileges, and Access Controls |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:6109 | |||
Oval ID: | oval:org.mitre.oval:def:6109 | ||
Title: | MSMQ Null Pointer Vulnerability | ||
Description: | The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel mode, which allows local users to gain privileges via a crafted request, aka "MSMQ Null Pointer Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2009-1922 | Version: | 3 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Vista Microsoft Windows Server 2003 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Os | 1 | |
Os | 1 | |
Os | 2 | |
Os | 2 |
OpenVAS Exploits
Date | Description |
---|---|
2009-08-13 | Name : Microsoft Windows Message Queuing Privilege Escalation Vulnerability (971032) File : nvt/secpod_ms09-040.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
56901 | Microsoft Windows Message Queuing Service (MSMQ) mqac.sys IOCTL Request Parsi... |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2009-08-11 | Name : Users can elevate their privileges on the remote host. File : smb_nt_ms09-040.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:10:40 |
|
2024-11-28 12:19:09 |
|
2021-05-04 12:09:40 |
|
2021-04-22 01:10:00 |
|
2020-05-23 00:23:53 |
|
2019-02-26 17:19:31 |
|
2018-10-13 00:22:49 |
|
2018-10-11 00:19:37 |
|
2017-09-29 09:24:15 |
|
2016-06-28 17:43:13 |
|
2016-04-26 18:52:31 |
|
2014-02-17 10:50:21 |
|
2013-05-10 23:51:49 |
|