CVE

Id
40088  
CVE No.
CVE-2009-2653  
Status
Candidate  
Description
** DISPUTED ** The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows local administrators to bypass unspecified "security software" and gain privileges via a crafted call that triggers an overwrite of an arbitrary memory location. NOTE: the vendor disputes the significance of this report, stating that "the Administrator to SYSTEM "escalation" is not a security boundary we defend."  
Phase
Assigned (20090803)  
Votes
None (candidate not yet proposed)  
Comments