Lucene search

K
cve[email protected]CVE-2010-1886
HistoryOct 03, 2022 - 4:20 p.m.

CVE-2010-1886

2022-10-0316:20:59
CWE-264
web.nvd.nist.gov
39
cve-2010-1886
microsoft windows
privilege escalation
networkservice
localsystem
security boundary

6.8 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:S/C:C/I:C/A:C

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

32.4%

Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2, and Windows 7 allow local users to gain privileges by leveraging access to a process with NetworkService credentials, as demonstrated by TAPI Server, SQL Server, and IIS processes, and related to the Windows Service Isolation feature. NOTE: the vendor states that privilege escalation from NetworkService to LocalSystem does not cross a “security boundary.”

Affected configurations

NVD
Node
microsoftwindows_2003_serversp2
OR
microsoftwindows_2003_serversp2itanium
OR
microsoftwindows_2003_serverMatch-sp2x64
OR
microsoftwindows_7Match-
OR
microsoftwindows_server_2008x32
OR
microsoftwindows_server_2008x64
OR
microsoftwindows_server_2008sp2itanium
OR
microsoftwindows_server_2008Matchr2itanium
OR
microsoftwindows_server_2008Matchr2x64
OR
microsoftwindows_vistasp1
OR
microsoftwindows_vistasp2
OR
microsoftwindows_xpsp2professional
OR
microsoftwindows_xpMatch-sp3

6.8 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:S/C:C/I:C/A:C

7.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

32.4%

Related for CVE-2010-1886