Oval Definition:oval:org.mitre.oval:def:1524
Revision Date:2012-11-19Version:47
Title:CSRSS Local Elevation of Privilege Vulnerability
Description:Use-after-free vulnerability in the Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Vista does not properly handle connection resources when starting and stopping processes, which allows local users to gain privileges by opening and closing multiple ApiPort connections, which leaves a "dangling pointer" to a process data structure.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2007-1209
Platform(s):Microsoft Windows Vista
Product(s):
Definition Synopsis
  • Windows Vista x86/x64
  • Microsoft Windows Vista is installed
  • OR Microsoft Windows Vista x64 Edition is installed
  • AND GRD/LDR version Check
  • The version of winsrv.dll is less than 6.0.6000.16445.
  • OR LDR version check
  • the version of winsrv.dll is greater than or equal 6.0.6000.20000
  • AND the version of winsrv.dll is less than 6.0.6000.20544
  • BACK