|
BugTraq
Windows Vista Power Management & Local Security Policy Jul 18 2008 02:39AM Abe Getchell (me abegetchell com) (3 replies) Re: Windows Vista Power Management & Local Security Policy Aug 01 2008 08:43PM William A. Rowe, Jr. (wrowe rowe-clan net) RE: Windows Vista Power Management & Local Security Policy Jul 27 2008 09:26PM Greg (bugtraq1 pchandyman com au) RE: Windows Vista Power Management & Local Security Policy Jul 19 2008 05:36AM Jim Harrison (Jim isatools org) (1 replies) RE: Windows Vista Power Management & Local Security Policy Jul 19 2008 07:33AM Abe Getchell (me abegetchell com) (1 replies) RE: Windows Vista Power Management & Local Security Policy Jul 19 2008 10:19PM Thor (Hammer of God) (thor hammerofgod com) (1 replies) RE: Windows Vista Power Management & Local Security Policy Jul 20 2008 07:32PM Abe Getchell (me abegetchell com) (1 replies) RE: Windows Vista Power Management & Local Security Policy Jul 20 2008 08:33PM Jim Harrison (Jim isatools org) (1 replies) RE: Windows Vista Power Management & Local Security Policy Jul 20 2008 10:04PM Abe Getchell (me abegetchell com) (1 replies) RE: Windows Vista Power Management & Local Security Policy Jul 22 2008 03:15PM James C. Slora Jr. (james slora phra com) (2 replies) RE: Windows Vista Power Management & Local Security Policy Jul 22 2008 10:37PM Abe Getchell (me abegetchell com) |
|
|
Privacy Statement |
Don'tet me wrong; I think it's quite valid for someone to report something they feel is a vuln; even (or maybe even especially) if they can't demonstrate an exploit based on it. There have been plenty of reports herein and without that were actually proven by others. This is one of the things that makes open discussion so valuable.
So far, no one has demonstrated an exploit that depends on this behavior _alone_.
Jim
________________________________________
From: James C. Slora Jr. [james.slora (at) phra (dot) com [email concealed]]
Sent: Tuesday, July 22, 2008 8:15 AM
To: bugtraq (at) securityfocus (dot) com [email concealed]
Subject: RE: Windows Vista Power Management & Local Security Policy
So is this the bottom line?
This is a security mechanism bug that might lead to privilege escalation
for arbitrary user processes. The OP has left it for others to determine
exploitability.
[ reply ]