VulnerabilityAnalyzed
CVE-2009-1123
Microsoft Windows Improper Input Validation Vulnerability
KEVHIGH 7.8EPSS 4.92%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability."
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 4.92% probability · 92th percentile
- CISA KEV
- Listed 3 March 2022 · due 24 March 2022
- Affected
- microsoft/windows 2000 · microsoft/windows server 2003 · microsoft/windows server 2008 · microsoft/windows vista · microsoft/windows xp
- Source
- secure@microsoft.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2009-1123
References
- http://osvdb.org/54940Broken Link
- http://secunia.com/advisories/35372Broken Link
- http://www.securitytracker.com/id?1022359Broken Link, Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA09-160A.htmlBroken Link, Third Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2009/1544Broken Link
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-025Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6206Broken Link
- http://osvdb.org/54940Broken Link
- http://secunia.com/advisories/35372Broken Link
- http://www.securitytracker.com/id?1022359Broken Link, Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA09-160A.htmlBroken Link, Third Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2009/1544Broken Link
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-025Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6206Broken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-1123US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.