CVE-2010-1886

Microsoft Windows - Local Privilege Escalation via NetworkService Process

Title source: llm
STIX 2.1

Description

Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2, and Windows 7 allow local users to gain privileges by leveraging access to a process with NetworkService credentials, as demonstrated by TAPI Server, SQL Server, and IIS processes, and related to the Windows Service Isolation feature. NOTE: the vendor states that privilege escalation from NetworkService to LocalSystem does not cross a "security boundary."

References (3)

Core 3
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/kb/982316
Patch, Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/kb/2264072

Scores

EPSS 0.0141
EPSS Percentile 70.0%

Details

CWE
CWE-264
Status published
Products (6)
microsoft/windows_2003_server (3 CPE variants)
microsoft/windows_7
microsoft/windows_server_2008 (3 CPE variants)
microsoft/windows_server_2008 r2 (2 CPE variants)
microsoft/windows_vista (2 CPE variants)
microsoft/windows_xp (2 CPE variants)
Published Aug 16, 2010
Tracked Since Feb 18, 2026