Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-444h-qfvw-6mmm

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estimate the number of characters that a different user entered at a runas.exe password prompt, related to a "benchmarking attack."

Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estimate the number of characters that a different user entered at a runas.exe password prompt, related to a "benchmarking attack."

EPSS

Процентиль: 75%
0.00914
Низкий

Дефекты

CWE-200

Связанные уязвимости

nvd
около 17 лет назад

Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all processes, which allows local users to obtain sensitive information, as demonstrated by reading the I/O Other Bytes column in Task Manager (aka taskmgr.exe) to estimate the number of characters that a different user entered at a runas.exe password prompt, related to a "benchmarking attack."

EPSS

Процентиль: 75%
0.00914
Низкий

Дефекты

CWE-200