Lucene search

K
cvelistMicrosoftCVELIST:CVE-2010-1886
HistoryOct 03, 2022 - 4:20 p.m.

CVE-2010-1886

2022-10-0316:20:59
microsoft
www.cve.org
cve-2010-1886
microsoft windows
privilege escalation
networkservice
local user
tapi server
sql server
iis
security boundary
windows service isolation

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

32.2%

Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2, and Windows 7 allow local users to gain privileges by leveraging access to a process with NetworkService credentials, as demonstrated by TAPI Server, SQL Server, and IIS processes, and related to the Windows Service Isolation feature. NOTE: the vendor states that privilege escalation from NetworkService to LocalSystem does not cross a β€œsecurity boundary.”

7.2 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

32.2%

Related for CVELIST:CVE-2010-1886