CVE-2009-1123

Confirmed PUBLISHED

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate...

Microsoft · Windows
Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
7.8 High

At a Glance

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability."

cisa windows
CVE Published
Jun 10, 2009
Exploitation Reported
Mar 03, 2022
CVSS
7.8 High
EPSS
Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • MS09-025 docs.microsoft.com · Vendor Advisory https://docs.microsoft.com/en-us/security-updates/securitybulletins/2...
  • 35372 secunia.com · Third-Party Advisory http://secunia.com/advisories/35372
  • TA09-160A us-cert.gov · Third-Party Advisory http://www.us-cert.gov/cas/techalerts/TA09-160A.html
  • 54940 osvdb.org · VDB Entry http://osvdb.org/54940
  • ADV-2009-1544 vupen.com · VDB Entry http://www.vupen.com/english/advisories/2009/1544
Show 2 more references
  • 1022359 securitytracker.com · VDB Entry http://www.securitytracker.com/id?1022359
  • oval:org.mitre.oval:def:6206 oval.cisecurity.org · VDB Entry https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.m...

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.