Oval Definition:oval:org.mitre.oval:def:777
Revision Date:2011-05-16Version:46
Title:Windows 2000 CSRSS Privilege Escalation Vulnerability
Description:Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides console window information with a long FaceName value.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2005-0551
Platform(s):Microsoft Windows 2000
Product(s):Client Server Runtime System (CSRSS)
Definition Synopsis
  • Windows 2000 (sp4 or earlier) is installed
  • Windows 2000 is installed
  • AND NOT Win2K/XP/2003 service pack 5 (or later) is installed
  • AND The version of Ntoskrnl.exe is less than 5.0.2195.7035
  • AND NOT the patch KB890859 is installed (Hotfix key)
  • BACK