Skip to main content

Microsoft Windows Client/Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

Last Update Date: 11 Jan 2012 11:04 Release Date: 11 Jan 2012 4537 Views

RISK: Medium Risk

TYPE: Operating Systems - Windows OS

TYPE: Windows OS

An elevation of privilege vulnerability exists in the Windows CSRSS due to the way that the CSRSS processes a sequence of specially crafted Unicode characters. An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.


Impact

  • Elevation of Privilege

System / Technologies affected

  • Windows XP
  • Windows Vista
  • Windows Server 2003
  • Windows Server 2008

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link