Cyber Resilience

CVE-2009-1123

Microsoft Windows Xp

CISA KEVActive ExploitationEUVD Exploited
Published
10 June 2009
Modified
22 April 2026
KEV Added
03 March 2022
Patch / advisory
CVSS Score v3.1 7.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score 0.049 91th percentile
Risk Priority 83 floored blend · peak EPSS

Summary

CVE-2009-1123 is a high-severity an unspecified weakness vulnerability in Microsoft Windows Xp. Its CVSS base score is 7.8 (High).

Operationally, ranked in the top 9% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

The vulnerability tracked as CVE-2009-1123 affects the kernel component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold through SP2, and Server 2008 SP2. It stems from improper validation of changes to unspecified kernel objects, which is tracked under the alias "Windows Kernel Desktop Vulnerability" and carries a CVSS 3.1 base score of 7.8.

Local users can exploit the flaw by running a crafted application on an affected system, resulting in an elevation of privileges that grants full control over the target host. The attack vector requires local access and some user interaction but does not need prior administrative rights.

Public advisories and technical alerts referencing the issue are available from sources such as US-CERT, SecurityTracker, Secunia, and OSVDB, providing further details on affected platforms and recommended actions.

EU & UK References

Vulnerability Data

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via…

more

a crafted application, aka "Windows Kernel Desktop Vulnerability."

CWE(s)
KEV Date Added
03 March 2022

Related Threats

CVEs Like This One

CVE-2008-4250Same product: Microsoft Windows 2000both on KEV
CVE-2010-0249Same product: Microsoft Windows 2000both on KEV
CVE-2010-0806Same product: Microsoft Windows 2000both on KEV
CVE-2010-2568Same product: Microsoft Windows Server 2003both on KEV
CVE-2012-0151Same product: Microsoft Windows Server 2003both on KEV
CVE-2011-3402Same product: Microsoft Windows Server 2003both on KEV
CVE-2010-4398Same product: Microsoft Windows Server 2003both on KEV
CVE-2012-4792Same product: Microsoft Windows Server 2003both on KEV
CVE-2010-3962Same product: Microsoft Windows Server 2003both on KEV
CVE-2012-4969Same product: Microsoft Windows Server 2003both on KEV

Affected Assets

microsoft
windows 2000
all versions
microsoft
windows server 2003
all versions
microsoft
windows server 2008
all versions
microsoft
windows vista
all versions
microsoft
windows xp
all versions

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References