| Vulnerability Name: | CVE-2004-2339 (CCN-15263) | ||||||||
| Assigned: | 2004-02-18 | ||||||||
| Published: | 2004-02-18 | ||||||||
| Updated: | 2019-04-30 | ||||||||
| Summary: | ** DISPUTED ** Microsoft Windows 2000, XP, and possibly 2003 allows local users with the SeDebugPrivilege privilege to execute arbitrary code as kernel and read or write kernel memory via the NtSystemDebugControl function, which does not verify its pointer arguments. Note: this issue has been disputed, since Administrator privileges are typically required to exploit this issue, thus privilege boundaries are not crossed. | ||||||||
| CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||
| References: | Source: CCN Type: BugTraq Mailing List, Wed Feb 18 2004 - 16:15:20 CST Multiple WinXP kernel vulns can give user mode programs kernel mode privileges Source: BUGTRAQ Type: UNKNOWN 20040219 RE: Multiple WinXP kernel vulns can give user mode programs kernel mode privileges Source: CCN Type: BugTraq Mailing List, Thu Feb 19 2004 - 08:01:04 CST RE: Multiple WinXP kernel vulns can give user mode programs kernel mode privileges Source: BUGTRAQ Type: UNKNOWN 20040219 RE: Multiple WinXP kernel vulns can give user mode programs kernel mode privileges Source: MITRE Type: CNA CVE-2004-2339 Source: CCN Type: SECTRACK ID: 1009128 Windows XP Kernel NtSystemDebugControl() Flaws Let Local Users With SeDebugPrivilege Execute Arbitrary Code in Kernel Mode Source: CCN Type: OSVDB ID: 19857 Microsoft Windows SeDebugPrivilege NtSystemDebugControl Function Privilege Escalation Source: BUGTRAQ Type: Vendor Advisory 20040218 Multiple WinXP kernel vulns can give user mode programs kernel mode privileges Source: CCN Type: BID-9694 Microsoft Windows NtSystemDebugControl() Kernel API Function Privilege Escalation Vulnerability Source: SECTRACK Type: UNKNOWN 1009128 Source: XF Type: UNKNOWN win-kernel-gain-privileges(15263) Source: XF Type: UNKNOWN win-kernel-gain-privileges(15263) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||