Back to search
CVE-2007-0843
Published: Feb 23, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
The ReadDirectoryChangesW API function on Microsoft Windows 2000, XP, Server 2003, and Vista does not check permissions for child objects, which allows local users to bypass permissions by opening a directory with LIST (READ) access and using ReadDirectoryChangesW to monitor changes of files that do not have LIST permissions, which can be leveraged to determine filenames, access times, and other sensitive information.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
22664
vdb-entry
x_refsource_BID
http://securityvulns.com/advisories/readdirectorychanges.asp
x_refsource_MISC
20070222 Microsoft Windows 2000/XP/2003/Vista ReadDirectoryChangesW informaton leak
mailing-list
x_refsource_FULLDISC
24245
third-party-advisory
x_refsource_SECUNIA
20070222 Microsoft Windows 2000/XP/2003/Vista ReadDirectoryChangesW informaton leak
mailing-list
x_refsource_BUGTRAQ
ADV-2007-0701
vdb-entry
x_refsource_VUPEN
33474
vdb-entry
x_refsource_OSVDB
win-readdirectory-information-disclosure(32644)
vdb-entry
x_refsource_XF
20070222 Re[2]: [Full-disclosure] Microsoft Windows 2000/XP/2003/Vista ReadDirectoryChangesW informaton leak
mailing-list
x_refsource_BUGTRAQ
2282
third-party-advisory
x_refsource_SREASON
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now