mAliCious Code 235
e above process allows exploitation of Windows by any user with
the SeImpersonate privilege; Microsoft released the MS09-012 advi-
sory to address this issue. is advisory makes architectural changes to
thwart token kidnapping related to the CVE-2009-0079 and CVE-
2009-0078 vulnerabilities. Both of these classify as service isolation
vulnerabilities because they allow two services running with the same
identity to access each other’s tokens.
37
e architectural change-back ports Vista’s Security Identifier
(SID) into previous versions of Windows to prevent services running
under the same account from accessing each other’s tokens. e SID
can include permissions within the process to allow only the process’
SID to have ...