CVE-2005-2827
The thread termination routine in the kernel for Windows NT 4.0 and 2000 (NTOSKRNL.EXE) allows local users to modify kernel memory and execution flow via steps in which a terminating thread causes Asynchronous Procedure Call (APC) entries to free the wrong data, aka the "Windows Kernel Vulnerability."
Date published : 2005-12-13
http://www.securityfocus.com/bid/15826
http://www.securityfocus.com/archive/1/419377/100/0/threaded