First published: Fri Jan 19 2007(Updated: )
Microsoft Windows XP and Windows Server 2003 do not properly handle user logoff, which might allow local users to gain the privileges of a previous system user, possibly related to user profile unload failure. NOTE: it is not clear whether this is an issue in Windows itself, or an interaction with another product. The issue might involve ZoneAlarm not being able to terminate processes when it cannot prompt the user.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2003 Server | =r2 | |
Microsoft Windows XP | =sp2 | |
Zonelabs ZoneAlarm |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0351 is classified as a medium severity vulnerability due to its potential to allow unauthorized privilege escalation.
To mitigate CVE-2007-0351, ensure that related Microsoft Windows XP and Windows Server 2003 systems are updated with the latest security patches.
CVE-2007-0351 primarily affects users of Microsoft Windows XP with Service Pack 2 and Windows Server 2003 R2.
CVE-2007-0351 is a privilege escalation vulnerability that occurs during improper handling of user logoff.
CVE-2007-0351 may also impact systems running Zonelabs ZoneAlarm, as it can interact with the user logoff process.