Security Advisory

CVE-2010-3961

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2010-12-16 19:00:00
Last updated 2024-08-07 03:26:12
Assigner microsoft
State PUBLISHED

Description

The Consent User Interface (UI) in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle an unspecified registry-key value, which allows local users with SeImpersonatePrivilege rights to gain privileges via a crafted application, aka "Consent UI Impersonation Vulnerability."