Overview
The Windows LSASS service contains privilege escalation vulnerability.
Description
The Windows Local Security Authority Subsystem Service (LSASS) is a process that enforces the local security policy. Per Microsoft Security Bulletin MS08-002: |
Impact
A local, authenticated attacker may be able gain elevated privileges or execute programs in the context of a different user. |
Solution
Update Microsoft has released an update to address this issue. See Microsoft Security Bulletin MS08-002 for more information. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Microsoft credits Thomas Garnier of SkyRecon for reporting this vulnerability.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | CVE-2007-5352 |
Severity Metric: | 1.50 |
Date Public: | 2008-01-08 |
Date First Published: | 2008-01-08 |
Date Last Updated: | 2008-01-08 20:57 UTC |
Document Revision: | 12 |