CVE-2007-3463
N/A
N/A
Summary
Microsoft Windows XP SP2 allows local users, who have sessions created by another user's RunAs (run as) command, to kill arbitrary processes of this other user, as demonstrated by the taskkill program. NOTE: the researcher claims a vendor dispute in which the vendor states that "RunAs and UAC are convenience features, not security boundaries. If you need a security guarantee, please log out and log back in with a different account.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://osvdb.org/39014
- http://www.securityfocus.com/archive/1/472282/100/0/threaded
- http://www.securityfocus.com/archive/1/472216/100/0/threaded
References
- http://osvdb.org/39014
- http://www.securityfocus.com/archive/1/472282/100/0/threaded
- http://www.securityfocus.com/archive/1/472216/100/0/threaded
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.