CVE-2010-1886 Information

Description

Microsoft Windows XP SP2 and SP3 Windows Server 2003 SP2 Windows Vista SP1 and SP2 Windows Server 2008 SP2 and R2 and Windows 7 allow local users to gain privileges by leveraging access to a process with NetworkService credentials as demonstrated by TAPI Server SQL Server and IIS processes and related to the Windows Service Isolation feature. NOTE: the vendor states that privilege escalation from NetworkService to LocalSystem does not cross a \security boundary.\

Reference

http://support.microsoft.com/kb/2264072 http://support.microsoft.com/kb/982316 http://www.microsoft.com/technet/security/advisory/2264072.mspx

Share on: