CVE-2011-0039

Microsoft Windows XP/Server 2003 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authentication requests, which allows local users to gain privileges via a request with a crafted length, aka "LSASS Length Validation Vulnerability."

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/46152
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/43253
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2011/0327
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1025049
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12537

Scores

EPSS 0.0192
EPSS Percentile 77.4%

Details

CWE
CWE-287
Status published
Products (2)
microsoft/windows_2003_server (3 CPE variants)
microsoft/windows_xp (2 CPE variants)
Published Feb 09, 2011
Tracked Since Feb 18, 2026