Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2010-3961 | First vendor Publication | 2010-12-16 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 7.2 | Attack Range | Local |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
The Consent User Interface (UI) in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle an unspecified registry-key value, which allows local users with SeImpersonatePrivilege rights to gain privileges via a crafted application, aka "Consent UI Impersonation Vulnerability." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3961 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-264 | Permissions, Privileges, and Access Controls |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:12323 | |||
Oval ID: | oval:org.mitre.oval:def:12323 | ||
Title: | Consent UI Impersonation Vulnerability | ||
Description: | The Consent User Interface (UI) in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle an unspecified registry-key value, which allows local users with SeImpersonatePrivilege rights to gain privileges via a crafted application, aka "Consent UI Impersonation Vulnerability." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2010-3961 | Version: | 11 |
Platform(s): | Microsoft Windows Vista Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 Microsoft Windows 7 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2010-12-15 | Name : Consent User Interface Privilege Escalation Vulnerability (2442962) File : nvt/secpod_ms10-100.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
69824 | Microsoft Windows Consent User Interface Local Privilege Escalation Microsoft Windows contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when an error in the User Account Control (UAC) Consent UI component when processing certain registry values occurs, allowing a local attacker to use a specially crafted program to gain elevated privileges and execute arbitrary code. |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2010-12-16 | IAVM : 2010-B-0117 - Microsoft Windows Consent User Interface Elevation of Privilege Vulnerability Severity : Category II - VMSKEY : V0025851 |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2010-12-15 | Name : A Windows component on the remote host is affected by a vulnerability that co... File : smb_nt_ms10-100.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:06:42 |
|
2024-11-28 12:23:21 |
|
2024-08-02 12:14:47 |
|
2024-08-02 01:04:03 |
|
2024-02-02 01:14:21 |
|
2024-02-01 12:03:58 |
|
2023-12-07 21:28:03 |
|
2023-09-05 12:13:22 |
|
2023-09-05 01:03:50 |
|
2023-09-02 12:13:27 |
|
2023-09-02 01:03:53 |
|
2023-08-12 12:15:59 |
|
2023-08-12 01:03:53 |
|
2023-08-11 12:13:29 |
|
2023-08-11 01:04:01 |
|
2023-08-06 12:12:59 |
|
2023-08-06 01:03:54 |
|
2023-08-04 12:13:04 |
|
2023-08-04 01:03:55 |
|
2023-07-14 12:13:01 |
|
2023-07-14 01:03:53 |
|
2023-03-29 01:14:55 |
|
2023-03-28 12:03:59 |
|
2022-10-11 12:11:37 |
|
2022-10-11 01:03:40 |
|
2021-05-04 12:12:37 |
|
2021-04-22 01:13:22 |
|
2020-05-23 00:26:46 |
|
2018-10-31 00:20:08 |
|
2018-10-13 00:23:01 |
|
2018-09-20 12:08:32 |
|
2017-09-19 09:24:02 |
|
2016-09-30 01:02:35 |
|
2016-08-31 12:02:19 |
|
2016-08-05 12:02:40 |
|
2016-06-28 18:21:27 |
|
2016-04-26 20:11:14 |
|
2014-02-17 10:58:16 |
|
2013-11-11 12:39:02 |
|
2013-05-10 23:35:35 |
|