SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2009-1123

Microsoft Windows Improper Input Validation Vulnerability

KEVHIGH 7.8EPSS 4.92%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 24 March 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability."

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
4.92% probability · 92th percentile
CISA KEV
Listed 3 March 2022 · due 24 March 2022
Affected
microsoft/windows 2000 · microsoft/windows server 2003 · microsoft/windows server 2008 · microsoft/windows vista · microsoft/windows xp
Source
secure@microsoft.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2009-1123

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.