CVE-2007-1209

Use-after-free vulnerability in the Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Vista does not properly handle connection resources when starting and stopping processes, which allows local users to gain privileges by opening and closing multiple ApiPort connections, which leaves a "dangling pointer" to a process data structure.
References
Link Resource
http://research.eeye.com/html/advisories/published/AD20070410b.html
http://secunia.com/advisories/24823
http://securityreason.com/securityalert/2531
http://www.kb.cert.org/vuls/id/219848 US Government Resource
http://www.osvdb.org/34008
http://www.securityfocus.com/archive/1/465233/100/0/threaded
http://www.securityfocus.com/archive/1/466331/100/200/threaded
http://www.securityfocus.com/archive/1/466331/100/200/threaded
http://www.securityfocus.com/bid/23338
http://www.securitytracker.com/id?1017897
http://www.us-cert.gov/cas/techalerts/TA07-100A.html US Government Resource
http://www.vupen.com/english/advisories/2007/1325 Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-021
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1524
http://research.eeye.com/html/advisories/published/AD20070410b.html
http://secunia.com/advisories/24823
http://securityreason.com/securityalert/2531
http://www.kb.cert.org/vuls/id/219848 US Government Resource
http://www.osvdb.org/34008
http://www.securityfocus.com/archive/1/465233/100/0/threaded
http://www.securityfocus.com/archive/1/466331/100/200/threaded
http://www.securityfocus.com/archive/1/466331/100/200/threaded
http://www.securityfocus.com/bid/23338
http://www.securitytracker.com/id?1017897
http://www.us-cert.gov/cas/techalerts/TA07-100A.html US Government Resource
http://www.vupen.com/english/advisories/2007/1325 Vendor Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-021
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1524
Configurations

Configuration 1 (hide)

cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:27

Type Values Removed Values Added
References () http://research.eeye.com/html/advisories/published/AD20070410b.html - () http://research.eeye.com/html/advisories/published/AD20070410b.html -
References () http://secunia.com/advisories/24823 - () http://secunia.com/advisories/24823 -
References () http://securityreason.com/securityalert/2531 - () http://securityreason.com/securityalert/2531 -
References () http://www.kb.cert.org/vuls/id/219848 - US Government Resource () http://www.kb.cert.org/vuls/id/219848 - US Government Resource
References () http://www.osvdb.org/34008 - () http://www.osvdb.org/34008 -
References () http://www.securityfocus.com/archive/1/465233/100/0/threaded - () http://www.securityfocus.com/archive/1/465233/100/0/threaded -
References () http://www.securityfocus.com/archive/1/466331/100/200/threaded - () http://www.securityfocus.com/archive/1/466331/100/200/threaded -
References () http://www.securityfocus.com/bid/23338 - () http://www.securityfocus.com/bid/23338 -
References () http://www.securitytracker.com/id?1017897 - () http://www.securitytracker.com/id?1017897 -
References () http://www.us-cert.gov/cas/techalerts/TA07-100A.html - US Government Resource () http://www.us-cert.gov/cas/techalerts/TA07-100A.html - US Government Resource
References () http://www.vupen.com/english/advisories/2007/1325 - Vendor Advisory () http://www.vupen.com/english/advisories/2007/1325 - Vendor Advisory
References () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-021 - () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-021 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1524 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1524 -

Information

Published : 2007-04-10 21:19

Updated : 2024-11-21 00:27


NVD link : CVE-2007-1209

Mitre link : CVE-2007-1209

CVE.ORG link : CVE-2007-1209


JSON object : View

Products Affected

microsoft

  • windows_vista
CWE
CWE-399

Resource Management Errors