Overview
The Microsoft Windows Client/Server Run-time Subsystem (CSRSS) process fails to properly handle error messages. This vulnerability may allow an attacker to execute arbitrary code.
Description
The Microsoft Client/Server Run-time Subsystem (CSRSS) is an essential subsystem. CSRSS is responsible for console windows and creating and deleting threads. According to Microsoft Security Bulletin MS07-021: |
Impact
A local authenticated attacker may be able to gain elevated privileges. |
Solution
Apply update from Microsoft |
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental |
References
Acknowledgements
Thanks to Microsoft for information that was used in this report. Microsoft credits eEye for reporting this vulnerability.
This document was written by Ryan Giobbi.
Other Information
| CVE IDs: | CVE-2007-1209 |
| Severity Metric: | 0.08 |
| Date Public: | 2007-04-10 |
| Date First Published: | 2007-04-10 |
| Date Last Updated: | 2007-04-11 17:42 UTC |
| Document Revision: | 13 |