Junglewise Threat Intelligence

CVE-2009-1123: Microsoft Windows Improper Input Validation Vulnerability

CVE-2009-1123 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2022-03-03

Technologies: Microsoft Windows 2000, Microsoft Windows, Microsoft Windows Server 2003, Microsoft Windows Server 2008, Microsoft Windows Vista, Microsoft Windows XP. Vendors: Microsoft.

Executive brief

The kernel in multiple versions of Microsoft Windows fails to properly validate changes to unspecified kernel objects. This flaw, known as the Windows Kernel Desktop Vulnerability, allows local users to gain elevated privileges by executing a specially crafted application.

Affected products

  • Microsoft Windows 2000 SP4
  • Microsoft Windows XP SP2, SP3
  • Microsoft Windows Server 2003 SP2
  • Microsoft Windows Vista Gold, SP1, SP2
  • Microsoft Windows Server 2008 SP2

Timeline

  • 2009-06-09: patched: Microsoft released security bulletin MS09-025 to address this issue.
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-03-03: disclosed: NVD publication date.

Related threats