LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2009-1123: Microsoft Windows Improper Input Validation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 3, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 24, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2009-1123 to its Known Exploited Vulnerabilities catalog on Mar 3, 2022, with a federal patch deadline of Mar 24, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application.

CVE-2009-1123 is an improper input validation weakness in the Microsoft Windows kernel. The kernel does not properly validate changes to unspecified kernel objects, which can let a local user raise privileges by running a crafted application. For IT and security teams this matters because a local foothold—through malware, a compromised account, or another vulnerability—can be turned into higher privileges on the host, expanding what an attacker can do on that system.

Public detail is limited to the kernel-level validation failure and local privilege gain. Confirm exact product editions, update packages, and any additional constraints against the vendor advisory before you act.

How it works

This issue is classed as CWE-20 (Improper Input Validation). In general terms for this weakness, the kernel accepts or applies changes to certain kernel objects without sufficient checks on the data or the caller’s rights. An attacker who can already run code as a local user supplies a crafted application that triggers those unchecked changes. Successful abuse elevates the attacker’s privileges on the same machine.

No remote exploitation path, specific object names, or exploit mechanics are provided in the available facts. Treat any deeper technical claims as unconfirmed until you verify them in the vendor advisory. The practical impact is local privilege escalation, which is commonly used after an initial compromise to disable defenses, access sensitive data, or persist.

Am I affected? How to find it in your systems

The vulnerability affects Microsoft Windows. Typical locations include workstations, member servers, domain controllers, and any virtual machines or images running Windows. Inventory every Windows host in your environment—physical, virtual, and golden images—using your asset management, configuration management, or endpoint management tools.

How to remediate

Patch first. Apply the updates Microsoft released for this vulnerability, following the vendor instructions exactly as stated in the advisory (CISA’s required action is to apply updates per vendor instructions). Use your standard deployment ring: pilot, then broad rollout, with reboot handling as required by the kernel update.

If you can't patch immediately

Compensating controls cannot fully replace a kernel fix but can lower likelihood and impact until you can patch.

Schedule the official update as soon as operationally possible; these controls are temporary.

If your data may have been exposed

Actively exploited local privilege-escalation vulnerabilities are often used after an initial breach to deepen access and move data. Known ransomware use is not documented for this CVE. If you suspect a host was compromised before patching, follow your incident-response process: isolate, preserve evidence, check for persistence and credential theft, and assess whether sensitive data left the system. As a simple additional check, you can run a free exposure scan of your email addresses against known breach data to see whether your credentials or identities appear in prior public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-20
Added to CISA KEVMar 3, 2022
Federal patch deadlineMar 24, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities