Overview
The Microsoft Client Server Runtime System (CSRSS) incorrectly validates certain messages potentially resulting in privilege elevation.
Description
CSRSS is the user-mode part of the Win32 subsystem. Win32.sys is the kernel-mode portion of the Win32 subsystem. The Win32 subsystem must be running at all times. CSRSS is responsible for console windows, for creating threads, for deleting threads, and for some parts of the 16-bit virtual MS-DOS environment. The CSRSS only responds to requests made by other processes on the local computer. |
Impact
Local authenticated users could potentially execute arbitrary code as privileged users, allowing them to gain complete control of the system. |
Solution
Apply a patch |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Microsoft who in turn thank David Fritz working with iDEFENSE for reporting the CSRSS Vulnerability.
This document was written by Robert Mead based on information provided by Microsoft.
Other Information
CVE IDs: | CVE-2005-0551 |
Severity Metric: | 2.43 |
Date Public: | 2005-04-12 |
Date First Published: | 2005-04-13 |
Date Last Updated: | 2005-05-17 14:10 UTC |
Document Revision: | 15 |