Description
The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authentication requests, which allows local users to gain privileges via a request with a crafted length, aka "LSASS Length Validation Vulnerability."
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/46152
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/43253
Vendor Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0327
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-014
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id?1025049
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12537
Scores
EPSS
0.0192
EPSS Percentile
77.4%
Details
CWE
CWE-287
Status
published
Products (2)
microsoft/windows_2003_server
(3 CPE variants)
microsoft/windows_xp
(2 CPE variants)
Published
Feb 09, 2011
Tracked Since
Feb 18, 2026