Vulnerability Name: | CCN-65972 | ||||||
Published: | 2011-03-08 | ||||||
Updated: | 2011-03-08 | ||||||
Summary: | Microsoft Windows could allow a local attacker to gain elevated privileges on the system, caused by insecure write permissions being set on the .NET Runtime Optimization Service application mscorsvw.exe. An attacker could exploit this vulnerability to execute arbitrary code on the system with SYSTEM-level privileges. | ||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||
CVSS v2 Severity: | 7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 6.1 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:POC/RL:U/RC:UR)
| ||||||
Vulnerability Consequences: | Gain Privileges | ||||||
References: | Source: CCN Type: Microsoft Web site Microsft Winodws Source: CCN Type: BID-46773 Microsoft .NET Runtime Optimization Service Local Privilege Escalation Vulnerability Source: XF Type: UNKNOWN ms-win-mscorsvw-priv-escalation(65972) Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [03-08-2011] | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |