CVE-2004-2339
HIGHMicrosoft Windows 2000, XP, and 2003 - Authenticated Arbitrary Code Execution via NtSystemDebugControl
Title source: llmDescription
Microsoft Windows 2000, XP, and possibly 2003 allows local users with the SeDebugPrivilege privilege to execute arbitrary code as kernel and read or write kernel memory via the NtSystemDebugControl function, which does not verify its pointer arguments. Note: this issue has been disputed, since Administrator privileges are typically required to exploit this issue, thus privilege boundaries are not crossed
References (5)
Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1009128
Third Party Advisory mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2004-02/0529.html
Vendor Advisory mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/354392
Third Party Advisory mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2004-02/0530.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15263
Scores
CVSS v3
8.4
EPSS
0.0143
EPSS Percentile
70.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
Status
published
Products (3)
microsoft/windows_2000
microsoft/windows_2003_server
r2
microsoft/windows_xp
Published
Dec 31, 2004
Tracked Since
Feb 18, 2026