Skip to main content

Microsoft Windows Event System Vulnerability( 13 August 2008 )

Last Update Date: 28 Jan 2011 Release Date: 13 Aug 2008 5234 Views

RISK: Medium Risk

1. Event System Vulnerability

A remote code execution vulnerability exists because the Microsoft Windows Event System does not correctly validate user subscriptions requests when created. The vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full administrative rights.

2. Event System Vulnerability

A remote code execution vulnerability exists because the Microsoft Windows Event System does not correctly validate the range of indexes when calling an array of function pointers. The vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full administrative rights.