Details about the MSFT December patches just showed up online. We will update this page as we find out more.
MS 05-55: Vulnerability in Windows Kernel Could Allow Elevation of Privilege.A vulnerability in the Asynchronous Procedure Call queue allows local users to escalate their privileges. A regular user (who has to be logged in first) could use this vulnerability to gain Administrator privileges.
Microsoft rates this vulnerability as "Important" as there is no direct remote vector to exploit this issue. However, coupled with an Internet Explorer vulnerability or similar issues, this could be used to gain Administrator privileges even if a user runs Internet Explorer as a less privileged user.
Note that remote exploit may be possible if user credentials are known.
Defending Web Applications Security Essentials - SANS Silicon Valley - Cupertino 2020
Dec 13th 2005
1 decade ago