Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2007-1209
Description:Use-after-free vulnerability in the Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Vista does not properly handle connection resources when starting and stopping processes, which allows local users to gain privileges by opening and closing multiple ApiPort connections, which leaves a "dangling pointer" to a process data structure.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2007-1209
BugTraq ID: 23338
http://www.securityfocus.com/bid/23338
Bugtraq: 20070410 EEYE: Windows Vista CSRSS Dangling Process Pointer Privilege Escalation (Google Search)
http://www.securityfocus.com/archive/1/465233/100/0/threaded
Cert/CC Advisory: TA07-100A
http://www.us-cert.gov/cas/techalerts/TA07-100A.html
CERT/CC vulnerability note: VU#219848
http://www.kb.cert.org/vuls/id/219848
HPdes Security Advisory: HPSBST02208
http://www.securityfocus.com/archive/1/466331/100/200/threaded
HPdes Security Advisory: SSRT071365
http://www.securityfocus.com/archive/1/466331/100/200/threaded
http://research.eeye.com/html/advisories/published/AD20070410b.html
Microsoft Security Bulletin: MS07-021
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-021
http://www.osvdb.org/34008
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1524
http://www.securitytracker.com/id?1017897
http://secunia.com/advisories/24823
http://securityreason.com/securityalert/2531
http://www.vupen.com/english/advisories/2007/1325




© 1998-2025 E-Soft Inc. All rights reserved.