7.2 High
CVSS2
Attack Vector
LOCAL
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:L/Au:N/C:C/I:C/A:C
6.3 Medium
AI Score
Confidence
Low
0.001 Low
EPSS
Percentile
22.9%
The Trace Events functionality in the kernel in Microsoft Windows XP SP3 does not properly perform type conversion, which causes integer truncation and insufficient memory allocation and triggers a buffer overflow, which allows local users to gain privileges via a crafted application, related to WmiTraceMessageVa, aka βWindows Kernel Integer Truncation Vulnerability.β
CPE | Name | Operator | Version |
---|---|---|---|
microsoft:windows_xp | microsoft windows xp | eq | * |
osvdb.org/70823
securityreason.com/securityalert/8110
support.avaya.com/css/P8/documents/100127248
www.securityfocus.com/archive/1/516276/100/0/threaded
www.securityfocus.com/bid/46136
www.securitytracker.com/id?1025046
www.vupen.com/english/advisories/2011/0324
www.zerodayinitiative.com/advisories/ZDI-11-064
docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-011
exchange.xforce.ibmcloud.com/vulnerabilities/64926
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11996