The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows local administrators to bypass unspecified security software and gain privileges via a crafted call that triggers an overwrite of an arbitrary memory location. NOTE: the vendor disputes the significance of this report, stating that the Administrator to SYSTEM escalation is not a security boundary we defend.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Windows_server_2003 | Microsoft | * | * |
Windows_xp | Microsoft | –sp2 (including) | –sp2 (including) |
Windows_xp | Microsoft | –sp3 (including) | –sp3 (including) |