Lucene search

K
cveMicrosoftCVE-2010-1895
HistoryAug 11, 2010 - 6:47 p.m.

CVE-2010-1895

2010-08-1118:47:50
CWE-264
microsoft
web.nvd.nist.gov
55
cve-2010-1895
win32k pool overflow
windows xp
windows server 2003
privilege escalation
nvd
security vulnerability
memory allocation

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

9.5%

The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly perform memory allocation before copying user-mode data to kernel mode, which allows local users to gain privileges via a crafted application, aka β€œWin32k Pool Overflow Vulnerability.”

Affected configurations

Nvd
Node
microsoftwindows_2003_serversp2
OR
microsoftwindows_2003_serversp2itanium
OR
microsoftwindows_server_2003sp2
OR
microsoftwindows_xpsp3
OR
microsoftwindows_xpMatch-sp2x64
VendorProductVersionCPE
microsoftwindows_2003_servercpe:/o:microsoft:windows_2003_server::sp2::
microsoftwindows_xp-cpe:/o:microsoft:windows_xp:-:sp2::
microsoftwindows_xpcpe:/o:microsoft:windows_xp::sp3::
microsoftwindows_server_2003cpe:/o:microsoft:windows_server_2003::sp2::

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

9.5%