{"cve":{"cve_id":"CVE-2009-1123","is_kev":true,"kev_date_added":"2022-03-03","kev_vendor_project":"Microsoft","kev_product":"Windows","kev_vulnerability_name":"Microsoft Windows Improper Input Validation Vulnerability","kev_short_description":"The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application.","kev_required_action":"Apply updates per vendor instructions.","kev_due_date":"2022-03-24","kev_known_ransomware":false,"kev_notes":"https://nvd.nist.gov/vuln/detail/CVE-2009-1123","kev_cwes":["CWE-20"],"epss_score":0.04918,"epss_percentile":0.90983,"epss_as_of":"2026-06-23","description":"The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka \"Windows Kernel Desktop Vulnerability.\"","published_at":"2009-06-10T18:00:00Z","last_modified_at":"2026-06-16T23:06:33.440000Z","cvss_v3_score":7.8,"cvss_v3_vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cvss_v3_severity":"HIGH","cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":"active","ssvc_automatable":false,"ssvc_technical_impact":"total","cwes":null,"nvd_references":["http://secunia.com/advisories/35372","http://osvdb.org/54940","http://www.vupen.com/english/advisories/2009/1544","https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-025","http://www.securitytracker.com/id?1022359","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6206","http://www.us-cert.gov/cas/techalerts/TA09-160A.html"],"vuln_status":"Analyzed","trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:31.350578Z","updated_at":"2026-06-28T23:04:58.043639Z"},"effective_severity":"HIGH","badges":["kev"],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"L","value_label":"Local"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"R","value_label":"Required"},{"metric":"S","name":"Scope","value":"U","value_label":"Unchanged"},{"metric":"C","name":"Confidentiality","value":"H","value_label":"High"},{"metric":"I","name":"Integrity","value":"H","value_label":"High"},{"metric":"A","name":"Availability","value":"H","value_label":"High"}]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"microsoft","vendor_name":"Microsoft","product_slug":"windows-2000","product_name":"windows_2000","version_start":null,"version_start_inclusive":null,"version_end":null,"version_end_inclusive":null,"cpe23_uri":"cpe:2.3:o:microsoft:windows_2000:-:sp4:*:*:*:*:*:*"},{"vendor_slug":"microsoft","vendor_name":"Microsoft","product_slug":"windows-server-2003","product_name":"windows_server_2003","version_start":null,"version_start_inclusive":null,"version_end":null,"version_end_inclusive":null,"cpe23_uri":"cpe:2.3:o:microsoft:windows_server_2003:-:sp2:*:*:*:*:*:*"},{"vendor_slug":"microsoft","vendor_name":"Microsoft","product_slug":"windows-server-2008","product_name":"windows_server_2008","version_start":null,"version_start_inclusive":null,"version_end":null,"version_end_inclusive":null,"cpe23_uri":"cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*"},{"vendor_slug":"microsoft","vendor_name":"Microsoft","product_slug":"windows-vista","product_name":"windows_vista","version_start":null,"version_start_inclusive":null,"version_end":null,"version_end_inclusive":null,"cpe23_uri":"cpe:2.3:o:microsoft:windows_vista:-:sp1:*:*:*:*:*:*"},{"vendor_slug":"microsoft","vendor_name":"Microsoft","product_slug":"windows-vista","product_name":"windows_vista","version_start":null,"version_start_inclusive":null,"version_end":null,"version_end_inclusive":null,"cpe23_uri":"cpe:2.3:o:microsoft:windows_vista:-:sp2:*:*:*:*:*:*"},{"vendor_slug":"microsoft","vendor_name":"Microsoft","product_slug":"windows-xp","product_name":"windows_xp","version_start":null,"version_start_inclusive":null,"version_end":null,"version_end_inclusive":null,"cpe23_uri":"cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:-:*:*:*"},{"vendor_slug":"microsoft","vendor_name":"Microsoft","product_slug":"windows-xp","product_name":"windows_xp","version_start":null,"version_start_inclusive":null,"version_end":null,"version_end_inclusive":null,"cpe23_uri":"cpe:2.3:o:microsoft:windows_xp:-:sp2:*:*:professional:*:*:*"},{"vendor_slug":"microsoft","vendor_name":"Microsoft","product_slug":"windows-xp","product_name":"windows_xp","version_start":null,"version_start_inclusive":null,"version_end":null,"version_end_inclusive":null,"cpe23_uri":"cpe:2.3:o:microsoft:windows_xp:-:sp3:*:*:*:*:*:*"}],"exploit_refs":[],"news":[],"references":[{"url":"http://secunia.com/advisories/35372","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://osvdb.org/54940","source_type":"MISC","tags":[]},{"url":"http://www.vupen.com/english/advisories/2009/1544","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-025","source_type":"MISC","tags":[]},{"url":"http://www.securitytracker.com/id?1022359","source_type":"MISC","tags":[]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6206","source_type":"MISC","tags":[]},{"url":"http://www.us-cert.gov/cas/techalerts/TA09-160A.html","source_type":"MISC","tags":[]}],"timeline":[{"type":"published","at":"2009-06-10T18:00:00Z","label":"CVE published","source":null},{"type":"cisa_reported","at":"2022-03-03T00:00:00Z","label":"Added to CISA KEV catalog","source":"kev"},{"type":"ssvc_changed","at":"2026-06-24T00:30:43.703670Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-24T00:30:43.703670Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-24T00:30:43.703670Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-06-24T00:30:43.703670Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-06-24T00:30:43.703670Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-06-24T00:30:43.703670Z","label":"CVSS score revised","source":"vulnrichment"}]}