CVE-2010-2744: High severity Microsoft Windows 2003 Server vulnerability
The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly manage a window class, which allows local users to gain privileges by creating a window, then using (1) the SetWindowLongPtr function to modify the popup menu structure, or (2) the SwitchWndProc function with a switch window information pointer, which is not re-initialized when a WMNCCREATE message is processed, aka "Win32k Window Class Vulnerability."
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must already be able to run code locally as a user on an affected Windows system. The issue is a local privilege-escalation flaw, not a remote access vulnerability.
Which systems are affected?
Affected systems include Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7.
What does exploitation allow?
Successful exploitation allows a local user to gain elevated privileges. The listed impact includes compromise of confidentiality, integrity, and availability.
What actions are involved in exploitation?
The attacker creates a window and then either uses SetWindowLongPtr to modify the popup menu structure or uses SwitchWndProc with a switch-window information pointer that is not re-initialized during WM_NCCREATE processing.