CVE-2009-0320: Infoleak
Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estimate the number of characters that a different user entered at a runas.exe password prompt, related to a "benchmarking attack."
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A local user can exploit it without authentication. The issue relies on observing I/O activity measurements for other processes through Task Manager.
What information can be inferred?
An attacker may estimate the number of characters another user enters at a runas.exe password prompt by monitoring the I/O Other Bytes measurement. The provided information describes an information disclosure impact, not password-content recovery.
Is remote exploitation described?
No. The supplied vector identifies local access (AV:L), and the description only demonstrates observation through the local Task Manager interface.