Security Advisory

CVE-2010-1886

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2010-08-16 18:25:00
Last updated 2024-09-16 20:36:20
Assigner microsoft
CVSS score not scored
State PUBLISHED

Description

Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2, and Windows 7 allow local users to gain privileges by leveraging access to a process with NetworkService credentials, as demonstrated by TAPI Server, SQL Server, and IIS processes, and related to the Windows Service Isolation feature. NOTE: the vendor states that privilege escalation from NetworkService to LocalSystem does not cross a "security boundary."