CVE-2009-1123
KEVmassLocal Privilege Escalation in Microsoft Windows Kernel
CISA: Microsoft Windows Improper Input Validation Vulnerability
CVE-2009-1123 is an input validation flaw in the Microsoft Windows kernel: the kernel does not properly validate changes to certain kernel objects. A local attacker triggers the flaw by running a specially crafted application on the target system, causing kernel object changes the kernel fails to check. Successful exploitation elevates the attacker from an ordinary user to kernel-level (administrator/SYSTEM) privileges, giving full control of the local machine. Any system running the affected Microsoft Windows versions is exposed, though the available data does not specify exact version ranges. CISA added this CVE to its Known Exploited Vulnerabilities catalog on 2022-03-03, confirming active exploitation, while no public proof-of-concept is known and ransomware use is unconfirmed.
What to do: Apply the latest Microsoft Windows security updates via Windows Update or the Microsoft Update Catalog, and consult Microsoft's advisory for CVE-2009-1123 to identify which bulletin applies to your Windows editions, since fixed versions are not specified here. Because exploitation requires local execution of a crafted application, restricting local logon rights on sensitive servers is a reasonable interim mitigation. Federal agencies must patch per the CISA KEV required-action deadline.
| Microsoft Windows | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application.
- Affected
- Microsoft Windows
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Microsoft
- Products
- Windows
- Weakness
- CWE-20