(MS10-099) Vulnerability in Routing and Remote Access Could Allow Elevation of Privilege (2440591)
Publish Date: 10 février 2011
Gravité: : Élevé
Identifiant(s) CVE: : CVE-2010-3963
Date du conseil: 10 février 2011
Description
This update resolves a vulnerability in the Routing and Remote Access NDProxy component of Microsoft Windows. An attacker with valid logon credentials could gain elevation of privilege by logging on locally and running a specially crafted application on the affected system. More specifically, this update addresses the vulnerability by correction the validation in the Routing and Remote Access component.
Information Exposure Rating:
For information on patches specific to the affected software, please proceed to the Microsoft Web page.
Solutions
Affected software and version:
- Windows XP Service Pack 3
- Windows XP Professional x64 Edition Service Pack 2
- Windows Server 2003 Service Pack 2
- Windows Server 2003 x64 Edition Service Pack 2
- Windows Server 2003 with SP2 for Itanium-based Systems