The POSIX component of Microsoft Windows NT and Windows 2000 allows local users to execute arbitrary code via certain parameters, possibly by modifying message length values and causing a buffer overflow.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HMicrosoft Interix
APPMicrosoft2.2Microsoft Windows 2000
OSMicrosoftall versionsMicrosoft Windows Nt
OSMicrosoft4.0
CISA KEV — detailsi
- Vendori
- Microsoft ↗
- Producti
- Windows
- Added to KEVi
- March 3, 2022
- Remediation deadline (US Federal)i
- March 24, 2022(overdue)
Apply updates per vendor instructions.
A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system.
Related vulnerabilities
RCE w usłudze Server systemu Windows przez przepełnienie bufora w RPC
Ukryte konto serwisowe w Schneider Electric TriStation umożliwia nieautoryzowany dostęp
RCE w Active Template Library (ATL) — błędne operacje zwalniania pamięci
RCE w usłudze SMB systemu Windows — błędna walidacja NT Trans2
Przepełnienie bufora sterty w GDI — podatność na RCE przez plik WMF