Oval Definition:oval:org.mitre.oval:def:3544
Revision Date:2011-05-16Version:47
Title:Windows XP CSRSS Privilege Escalation Vulnerability
Description:Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2005-0551
Platform(s):Microsoft Windows XP
Product(s):Client Server Runtime System (CSRSS)
Definition Synopsis
  • Windows XP is installed
  • AND NOT the patch KB890859 is installed (Hotfix key)
  • AND Windows No Service Pack or Service Pack 1 and Ntoskrnl.exe version less than 5.1.2600.1634
  • Windows No Service Pack or Service Pack 1
  • Win2K/XP/2003/Vista service pack 1 is installed
  • OR NOT Win2K/XP/2003 service pack 1 (or later) is installed
  • AND The version of Ntoskrnl.exe is less than 5.1.2600.1634
  • BACK