CVE

Id
24566  
CVE No.
CVE-2007-1209  
Status
Candidate  
Description
Use-after-free vulnerability in the Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Vista does not properly handle connection resources when starting and stopping processes, which allows local users to gain privileges by opening and closing multiple ApiPort connections, which leaves a "dangling pointer" to a process data structure.  
Phase
Assigned (20070302)  
Votes
None (candidate not yet proposed)  
Comments