The Message Queuing (aka MSMQ) service for Microsoft Windows 2000...
Vulnerability Description
The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel mode, which allows local users to gain privileges via a crafted request, aka "MSMQ Null Pointer Vulnerability."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-1922
Credits & Attribution
No credits recorded in the NVD database.
References
- http://osvdb.org/56901
- http://www.us-cert.gov/cas/techalerts/TA09-223A.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-040
- http://secunia.com/advisories/36214
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6109
- http://www.securityfocus.com/archive/1/505691/100/0/threaded
- http://www.securitytracker.com/id?1022714
- http://en.securitylab.ru/lab/PT-2008-09
More from microsoft
View All →Affected Vendor
microsoft
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.