CVE detail
CVE-2009-2653 — CVE-2009-2653
Published 2009-08-03 · Modified 2026-06-16 · Vendor microsoft · Product windows_server_2003 · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0593
EPSS probability
exploitation probability, 30d
93.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows local administrators to bypass unspecified "security software" and gain privileges via a crafted call that triggers an overwrite of an arbitrary memory location. NOTE: the vendor disputes the significance of this report, stating that 'the Administrator to SYSTEM "escalation" is not a security boundary we defend.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References