CVE-2007-1206

Description

The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0; 2000 SP4; XP SP2; Server 2003, 2003 SP1, and 2003 SP2; and Windows Vista before June 2006; uses insecure permissions (PAGE_READWRITE) for a physical memory view, which allows local users to gain privileges by modifying the zero page during a race condition before the view is unmapped.

Risk Information

Base Score
8.1
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS Score
Exploitation Probability
1.753

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Windows 2000 (KB931784)Windows
Security Update for Windows XP (KB931784)Windows
Security Update for Windows Server 2003 (KB931784) x86 based systemsWindows
Security Update for Windows Server 2003 (KB931784) x86 based systems for SP1Windows
Security Update for Windows Server 2003 (KB931784) x86 based systems for SP2Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234