CVE-2010-3961Microsoft Windows Server 2008 vulnerability

CWE-2644 documents4 sources
Severity
7.2HIGHNVD
EPSS
0.7%
top 26.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 16
Latest updateMay 14

Description

The Consent User Interface (UI) in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle an unspecified registry-key value, which allows local users with SeImpersonatePrivilege rights to gain privileges via a crafted application, aka "Consent UI Impersonation Vulnerability."

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages1 packages

🔴Vulnerability Details

1
GHSA
GHSA-gwxq-9r35-f7xv: The Consent User Interface (UI) in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle2022-05-14

💥Exploits & PoCs

1
Exploit-DB
McAfee Subscription Manager - Remote Stack Buffer Overflow (Metasploit)2010-07-03

🕵️Threat Intelligence

1
Zscaler
Zscaler found Multiple Security Vulnerabilities | 12-14-2010