First published: Sat Jun 24 2006(Updated: )
** DISPUTED ** The Task scheduler (at.exe) on Microsoft Windows XP spawns each scheduled process with SYSTEM permissions, which allows local users to gain privileges. NOTE: this issue has been disputed by third parties, who state that the Task scheduler is limited to the Administrators group by default upon installation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows XP | =gold | |
=gold |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3209 is considered to have a moderate severity due to its potential to allow local users to gain SYSTEM privileges.
To mitigate CVE-2006-3209, restrict access to the Task Scheduler for non-administrative users and apply relevant security updates for Windows XP.
CVE-2006-3209 affects users of Microsoft Windows XP running the gold version.
CVE-2006-3209 is a privilege escalation vulnerability that can allow local users to execute processes with elevated permissions.
While exploits for CVE-2006-3209 have been discussed, it is recommended to apply preventive measures rather than rely on exploit information.