MS11-010 - Elevated privileges vulnerability in the Microsoft Windows Client/Server Run-time Subsystem (CSRSS) in Windows XP and Windows Server 2003ID: oval:org.secpod.oval:def:89 | Date: (C)2011-02-09 (M)2022-10-10 |
Class: VULNERABILITY | Family: windows |
The host is installed with Windows Client/Server Run-time Subsystem (CSRSS) in Windows XP and Windows Server 2003 and is prone to elevated privileges vulnerability. A flaw is present in CSRSS, which fails to handle a specially crafted application that continues to run even after log off. Successful exploitation could allow attackers to obtain elevated privileges by starting the application and acquire the logon credentials of subsequent users. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.
Platform: |
Microsoft Windows Server 2003 |
Microsoft Windows XP |
Product: |
Windows Client/Server Run-time Subsystem |