Summary
This host is missing a critical security update according to Microsoft Bulletin MS11-010.
Impact
Successful exploitation could allow local attackers to obtain sensitive information or gain privileges.
Impact Level: System/Application
Solution
Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link, http://www.microsoft.com/technet/security/Bulletin/MS11-010.mspx
Insight
The flaw is caused by an error in the Client/Server Run-time Subsystem(CSRSS) when terminating a process when a user logs off, which could allow malicious users to monitor the actions of a user who subsequently logged on to the system, and collect useful information to try to further compromise the affected system.
Affected
Microsoft Windows XP Service Pack 3 and prior.
Microsoft Windows 2003 Service Pack 2 and prior.
References
Severity
Classification
-
CVE CVE-2011-0030 -
CVSS Base Score: 4.7
AV:L/AC:M/Au:N/C:C/I:N/A:N
Related Vulnerabilities
- Microsoft 'ISATAP' Component Spoofing Vulnerability (978338)
- Microsoft SharePoint Server HTML Sanitisation Component XSS Vulnerability (2821818)
- Microsoft SharePoint Server Remote Code Execution Vulnerability (2904244)
- Microsoft SharePoint Privilege Elevation Vulnerabilities (2663841)
- Microsoft InfoPath HTML Sanitisation Component XSS Vulnerability (2821818)