Lucene search

K
nvd[email protected]NVD:CVE-2006-0023
HistoryFeb 08, 2006 - 2:18 a.m.

CVE-2006-0023

2006-02-0802:18:00
CWE-264
web.nvd.nist.gov
4

CVSS2

4.3

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:S/C:P/I:P/A:P

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

32.5%

Microsoft Windows XP SP1 and SP2 before August 2004, and possibly other operating systems and versions, uses insecure default ACLs that allow the Authenticated Users group to gain privileges by modifying critical configuration information for the (1) Simple Service Discovery Protocol (SSDP), (2) Universal Plug and Play Device Host (UPnP), (3) NetBT, (4) SCardSvr, (5) DHCP, and (6) DnsCache services, aka “Permissive Windows Services DACLs.” NOTE: the NetBT, SCardSvr, DHCP, DnsCache already require privileged access to exploit.

Affected configurations

Nvd
Node
microsoftwindows_xpsp1tablet_pc
OR
microsoftwindows_xpsp2tablet_pc
VendorProductVersionCPE
microsoftwindows_xp*cpe:2.3:o:microsoft:windows_xp:*:sp1:tablet_pc:*:*:*:*:*
microsoftwindows_xp*cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*

References

CVSS2

4.3

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:S/C:P/I:P/A:P

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

32.5%