Windows Keyboard Event Privilege Escalation Vulnerability

  
Affected System: Microsoft Windows XP SP2 Microsoft Windows XP SP1 Microsoft Windows XP Microsoft Windows Server 2003 SP1 Microsoft Windows Server 2003 Microsoft Windows 2000 SP4 Microsoft Windows 2000 SP3 Microsoft Windows 2000 SP2 Microsoft Windows 2000 SP1 Microsoft Windows 2000 Microsoft Windows Detailed Description : Microsoft Windows is a very popular operating system released by Microsoft. A privilege elevation vulnerability exists in Microsoft Windows that allows an attacker to send malicious code events to a desktop application running at a higher level (such as explorer.exe), causing arbitrary code to be executed with the privileges of the target user. The cause is a design error when the desktop application processes keyboard events sent via the keybd_event() function. In the current Microsoft security model, messages can be sent between applications sharing a desktop, each desktop application can process every process executed on the same desktop, and any application can simulate virtual by sending a keyboard tap action The keyboard, which allows each process to send messages and keystrokes as interactive users.
Copyright © Windows knowledge All Rights Reserved