Skip to main content

Microsoft Windows Client/Server Runtime Subsystem Elevation of Privilege Vulnerability

Last Update Date: 14 Dec 2011 14:49 Release Date: 14 Dec 2011 4825 Views

RISK: High Risk

TYPE: Operating Systems - Application Platforms

TYPE: Application Platforms

An elevation of privilege vulnerability exists in the Client/Server Run-time Subsystem (CSRSS), allowing arbitrary code to be executed in the context of another process. If this process runs with administrator privileges, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.


Impact

  • Elevation of Privilege

System / Technologies affected

  • Windows XP
  • Windows Vista
  • Windows 7
  • Windows Server 2003
  • Windows Server 2008
  • Windows Server 2008 R2

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link