ZeroHour

CVE-2009-1123

KEVmass

Local Privilege Escalation in Microsoft Windows Kernel

CISA: Microsoft Windows Improper Input Validation Vulnerability

CVSS
EPSS
5%p92
Published
KEV added
AI analysis

CVE-2009-1123 is an input validation flaw in the Microsoft Windows kernel: the kernel does not properly validate changes to certain kernel objects. A local attacker triggers the flaw by running a specially crafted application on the target system, causing kernel object changes the kernel fails to check. Successful exploitation elevates the attacker from an ordinary user to kernel-level (administrator/SYSTEM) privileges, giving full control of the local machine. Any system running the affected Microsoft Windows versions is exposed, though the available data does not specify exact version ranges. CISA added this CVE to its Known Exploited Vulnerabilities catalog on 2022-03-03, confirming active exploitation, while no public proof-of-concept is known and ransomware use is unconfirmed.

What to do: Apply the latest Microsoft Windows security updates via Windows Update or the Microsoft Update Catalog, and consult Microsoft's advisory for CVE-2009-1123 to identify which bulletin applies to your Windows editions, since fixed versions are not specified here. Because exploitation requires local execution of a crafted application, restricting local logon rights on sensitive servers is a reasonable interim mitigation. Federal agencies must patch per the CISA KEV required-action deadline.

Affected
Microsoft Windows
Estimated exposure
massHundreds of millions of Windows systems potentially affected (Windows install base exceeds 1 billion devices) — Windows runs on well over one billion devices worldwide, so even the subset of editions carrying this kernel flaw plausibly numbers in the hundreds of millions of installations, though the affected versions are unspecified.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Microsoft
Products
Windows
Weakness
CWE-20

In the news