A person named Ruben Santamarta has recently discovered a flaw in Microsoft Windows which let local users acquire sensitive information.

The affected Windows operating systems are:
-2000 Advanced Server
-2000 Datacenter Server
-2000 Pro
-2000 Server
-XP Home
-XP Pro

The flaw is based on an executable file which is CSRSS.exe. When the method NtRaiseHardError is used, CSRSS.exe does not do a proper validation on the arguments that will be passed through this method. Therefore, the process memory of CSRSS can be viewed.

Both Windows 2000 SP4 and XP SP2 has been tested and both got positive results.