First published: Wed Feb 09 2011(Updated: )
The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authentication requests, which allows local users to gain privileges via a request with a crafted length, aka "LSASS Length Validation Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Server 2003 | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
Microsoft Windows Server 2003 | =sp2 | |
Microsoft Windows Server 2003 | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0039 is considered a critical vulnerability due to its potential to allow unauthorized privilege escalation.
To fix CVE-2011-0039, it is recommended to apply the latest security updates provided by Microsoft for affected versions of Windows XP and Windows Server 2003.
CVE-2011-0039 affects local users of Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 without the latest security patches.
CVE-2011-0039 is a privilege escalation vulnerability found in the Local Security Authority Subsystem Service (LSASS) of affected Windows systems.
CVE-2011-0039 was reported in January 2011, highlighting a critical flaw in older Microsoft operating systems.