CVE-2008-2252

Description

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate parameters sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Corruption Vulnerability."

References

PatchThird Party AdvisoryVDB Entry
PatchVendor Advisory
Third Party AdvisoryVDB Entry
Mailing ListThird Party Advisory
Third Party AdvisoryUS Government Resource
Broken Link
VDB Entry
VDB Entry
Third Party Advisory
PatchVendor Advisory

CvssV3 impact

Could not find any metrics

CvssV2 impact

Version

2.0

VectorString

AV:L/AC:L/Au:N/C:C/I:C/A:C

AccessVector

LOCAL

AccessComplexity

LOW

Authentication

NONE

ConfidentialityImpact

COMPLETE

IntegrityImpact

COMPLETE

AvailabilityImpact

COMPLETE

BaseScore

7.199999809265137