CVE-2009-1922

Microsoft Windows - Privilege Escalation

Title source: llm
STIX 2.1

Description

The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel mode, which allows local users to gain privileges via a crafted request, aka "MSMQ Null Pointer Vulnerability."

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/56901
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA09-223A.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36214
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6109
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/505691/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1022714
Various Sources x_refsource_misc
http://en.securitylab.ru/lab/PT-2008-09

Scores

EPSS 0.0135
EPSS Percentile 68.7%

Details

CWE
CWE-264
Status published
Products (4)
microsoft/windows_2000
microsoft/windows_server_2003
microsoft/windows_vista (2 CPE variants)
microsoft/windows_xp (2 CPE variants)
Published Aug 12, 2009
Tracked Since Feb 18, 2026