First published: Fri Dec 31 2004(Updated: )
** DISPUTED ** Microsoft Windows 2000, XP, and possibly 2003 allows local users with the SeDebugPrivilege privilege to execute arbitrary code as kernel and read or write kernel memory via the NtSystemDebugControl function, which does not verify its pointer arguments. Note: this issue has been disputed, since Administrator privileges are typically required to exploit this issue, thus privilege boundaries are not crossed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2000 | ||
Microsoft Windows Server 2003 | =r2 | |
Microsoft Windows XP | =gold |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2339 is considered a critical vulnerability due to its potential for local users to execute arbitrary code with kernel privileges.
To fix CVE-2004-2339, it is recommended to apply the latest security patches provided by Microsoft for the affected Windows versions.
CVE-2004-2339 affects Microsoft Windows 2000, Windows XP, and potentially Windows 2003 Server R2.
The vulnerability in CVE-2004-2339 allows local users with SeDebugPrivilege to execute arbitrary code and manipulate kernel memory through improper pointer validation.
Yes, CVE-2004-2339 is noted as disputed, meaning there are differing opinions on the severity and exploitability of the vulnerability.