Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly kill processes after a logout, which allows local users to obtain sensitive information or gain privileges via a crafted application that continues to execute throughout the logout of one user and the login session of the next user, aka "CSRSS Local Privilege Elevation Vulnerability."
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Microsoft Windows CSRSS本地权限提升漏洞
Vulnerability Description
Microsoft Windows是Microsoft发布的非常流行的操作系统。 当用户注销时Windows客户端/服务器运行时环境子系统(CSRSS)没有正确的终止用户进程,这可能允许本地用户以其他用户的权限执行任意代码。 如果要利用这个漏洞,攻击者首先要登录到系统,之后启动在注销后仍可继续运行的应用程序。当新的用户以自己的凭据登录后,攻击者的进程就可以监控新登录用户所执行的所有操作。如果该用户为管理员,攻击者就可以利用监控到的信息进一步入侵系统。
CVSS Information
N/A
Vulnerability Type
N/A