AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2009-2653

MEDIUM · CVSS 4.6 EPSS 5.93% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-08-03 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2009-2653
Severity
MEDIUM
CVSS
4.6
EPSS
5.93%
Microsoft Windows

Original NVD Description

The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows local administrators to bypass unspecified "security software" and gain privileges via a crafted call that triggers an overwrite of an arbitrary memory location. NOTE: the vendor disputes the significance of this report, stating that 'the Administrator to SYSTEM "escalation" is not a security boundary we defend.