← All CVEs

CVE-2008-1436

high · 9

Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalService accounts, which might allow context-dependent attackers to gain privileges by using one service process to capture a resource from a second service process that has a LocalSystem privilege-escalation ability, related to improper management of the SeImpersonatePrivilege user right, as originally reported for Internet Information Services (IIS), aka Token Kidnapping.

9
CVSS
36.8%
EPSS (exploit prob.)
98th
EPSS percentile
2008-04-21
Published

AV:N/AC:L/Au:S/C:C/I:C/A:C

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
microsoftwindows-ntvista
microsoftwindows-ntvista
microsoftwindows-ntvista
microsoftwindows_server_2003all versions
microsoftwindows_server_2003all versions
microsoftwindows_server_2003all versions
microsoftwindows_server_2003all versions
microsoftwindows_server_2008all versions
microsoftwindows_server_2008all versions
microsoftwindows_server_2008all versions
microsoftwindows_vistaall versions
microsoftwindows_vistaall versions
microsoftwindows_xpall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-1436