CVE Vulnerabilities

CVE-2010-1886

Published: Aug 16, 2010 | Modified: Dec 07, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:L/AC:L/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2, and Windows 7 allow local users to gain privileges by leveraging access to a process with NetworkService credentials, as demonstrated by TAPI Server, SQL Server, and IIS processes, and related to the Windows Service Isolation feature. NOTE: the vendor states that privilege escalation from NetworkService to LocalSystem does not cross a security boundary.

Affected Software

Name Vendor Start Version End Version
Windows_2003_server Microsoft * *
Windows_2003_server Microsoft –sp2 (including) –sp2 (including)
Windows_7 Microsoft - (including) - (including)
Windows_server_2008 Microsoft * *
Windows_server_2008 Microsoft r2 (including) r2 (including)
Windows_vista Microsoft * *
Windows_xp Microsoft * *
Windows_xp Microsoft –sp3 (including) –sp3 (including)

References