peter bassill · operator
$ cve CVE-2008-1436 JSON

CVE-2008-1436 EXPLOIT

9.0
HIGH · CVSS 2.0 · EPSS 36.8% (pctl 98)

Patch early

A public exploit exists.

Description

Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalService accounts, which might allow context-dependent attackers to gain privileges by using one service process to capture a resource from a second service process that has a LocalSystem privilege-escalation ability, related to improper management of the SeImpersonatePrivilege user right, as originally reported for Internet Information Services (IIS), aka Token Kidnapping.

Scoring

CVSS9.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS36.83% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2008-04-21
Last modified2026-06-16

Affected (5)

VendorProduct
microsoftwindows server 2003
microsoftwindows server 2008
microsoftwindows vista
microsoftwindows xp
microsoftwindows-nt

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD