CVE-2010-1886
Microsoft Windows - Local Privilege Escalation via NetworkService Process
Title source: llmDescription
Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2, and Windows 7 allow local users to gain privileges by leveraging access to a process with NetworkService credentials, as demonstrated by TAPI Server, SQL Server, and IIS processes, and related to the Windows Service Isolation feature. NOTE: the vendor states that privilege escalation from NetworkService to LocalSystem does not cross a "security boundary."
References (3)
Core 3
Core References
Patch, Vendor Advisory vendor-advisory
x_refsource_mskb
http://support.microsoft.com/kb/982316
Patch, Vendor Advisory vendor-advisory
x_refsource_mskb
http://support.microsoft.com/kb/2264072
Vendor Advisory x_refsource_confirm
http://www.microsoft.com/technet/security/advisory/2264072.mspx
Scores
EPSS
0.0141
EPSS Percentile
70.0%
Details
CWE
CWE-264
Status
published
Products (6)
microsoft/windows_2003_server
(3 CPE variants)
microsoft/windows_7
microsoft/windows_server_2008
(3 CPE variants)
microsoft/windows_server_2008
r2 (2 CPE variants)
microsoft/windows_vista
(2 CPE variants)
microsoft/windows_xp
(2 CPE variants)
Published
Aug 16, 2010
Tracked Since
Feb 18, 2026