CVE-2009-0320
Published Jan 28, 2009
Last updated 6 years ago
Overview
- Description
- Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estimate the number of characters that a different user entered at a runas.exe password prompt, related to a "benchmarking attack."
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4
- Impact score
- 6.9
- Exploitability score
- 1.9
- Vector string
- AV:L/AC:H/Au:N/C:C/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-200
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:microsoft:windows_server_2003:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "31A64C69-D182-4BEC-BA8A-7B405F5B2FC0" }, { "criteria": "cpe:2.3:o:microsoft:windows_server_2008:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6B33C9BD-FC34-4DFC-A81F-C620D3DAA79D" }, { "criteria": "cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3852BB02-47A1-40B3-8E32-8D8891A53114" }, { "criteria": "cpe:2.3:o:microsoft:windows_xp:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E61F1C9B-44AF-4B35-A7B2-948EEF7639BD" } ], "operator": "OR" } ] } ]