Skip to main content

CVE-2009-1123

7.8
HIGHCVSS v3.1 Base Score
5.17%
LOW RiskEPSS (90th percentile)
KEV
NVD-CWE-noinfo

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability."

Published: 6/10/2009
Modified: 10/22/2025
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

Microsoft Windows Improper Input Validation Vulnerability

Vendor / Product:

Microsoft Windows

Required Action:

Apply updates per vendor instructions.

Due Date: 3/24/2022(OVERDUE)
Added to KEV:

3/3/2022

Notes:

https://nvd.nist.gov/vuln/detail/CVE-2009-1123

Vulnerability Summary

CVSS v3 Score

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2 Score

7.2

AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

5.17%LOW Exploitation Risk
90th percentile

This vulnerability has a 5.17% probability of being exploited in the next 30 days, ranking higher than 90% of all scored CVEs.

CWE Classification

NVD-CWE-noinfo

Related Vulnerabilities