Total vulnerabilities in the database
Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 do not properly enforce AppLocker rules, which allows local users to bypass intended access restrictions via a (1) macro or (2) scripting feature in an application, as demonstrated by Microsoft Office applications and the SANDBOX_INERT and LOAD_IGNORE_CODE_AUTHZ_LEVEL flags.
Software | From | Fixed in |
---|---|---|
microsoft / windows_server_2008 | r2 | r2.x |
microsoft / windows_7 | --sp1 | --sp1.x |
microsoft / windows_7 | - | - |
microsoft / windows_server_2008 | r2-sp1 | r2-sp1.x |