The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0; 2000 SP4; XP SP2; Server 2003, 2003 SP1, and 2003 SP2; and Windows Vista before June 2006; uses insecure permissions (PAGE_READWRITE) for a physical memory view, which allows local users to gain privileges by modifying the "zero page" during a race condition before the view is unmapped.
2007-04-10T21:19:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 7.2 (HIGH)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | microsoft | windows_2000 | * | Yes |
Operating System | microsoft | windows_2003_server | gold | Yes |
Operating System | microsoft | windows_2003_server | sp1 | Yes |
Operating System | microsoft | windows_2003_server | sp2 | Yes |
Operating System | microsoft | windows_xp | * | Yes |