Vulnerability record · CVE-2009-1123 · published 10 June 2009
CVE-2009-1123: Microsoft Windows kernel improper validation allows local privilege escalation
Microsoft · Windows 2000
The Windows kernel fails to properly validate changes to unspecified kernel objects, letting a local user elevate privileges through a crafted application. The flaw affects Windows 2000 SP4, XP SP2/SP3, Server 2003 SP2, Vista Gold/SP1/SP2, and Server 2008 SP2. It matters because successful exploitation yields full control of the affected system.
Description
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability."
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is a KEV-listed local privilege escalation with high CVSS impact, though it requires local access and user interaction and affects only legacy Windows versions.
What it is
The Windows kernel fails to properly validate changes to unspecified kernel objects, letting a local user elevate privileges through a crafted application. The flaw affects Windows 2000 SP4, XP SP2/SP3, Server 2003 SP2, Vista Gold/SP1/SP2, and Server 2008 SP2. It matters because successful exploitation yields full control of the affected system.
Impact
An attacker who runs code locally can gain elevated privileges, typically SYSTEM-level access, on the vulnerable host. That access can be used to disable security controls, install persistence, or move laterally.
Attack surface
Reached locally by executing a crafted application on the target machine; the CVSS vector shows no privileges required but user interaction is needed. No remote or network vector is described.
Exploitation
CVE-2009-1123 is listed in CISA KEV (added 2022-03-03), indicating known exploitation in the wild. EPSS 30-day probability is about 4.9 percent (91.7th percentile), and no ransomware campaign use is documented.
What to do
- Apply the Microsoft MS09-025 security update to all affected Windows versions.
- Retire or isolate unsupported platforms (Windows 2000, XP, Server 2003) that cannot be patched.
- Restrict interactive logon and local execution rights to trusted users only.
- Monitor for and block execution of untrusted binaries on endpoints.
- Verify patch status across the listed OS versions with an authenticated vulnerability scan.
Detection
- Alert on unexpected privilege escalation or SYSTEM token acquisition by non-system processes.
- Monitor process creation for suspicious binaries launched from user-writable paths.
- Audit Windows security event logs for anomalous token or privilege changes.
- Correlate local exploit indicators with KEV-listed CVE scanning results.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2009-1123 to the Known Exploited Vulnerabilities catalog on 3 March 2022 as "Microsoft Windows Improper Input Validation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 24 March 2022.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-1123 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-1123), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.