Microsoft Windows 2003 Services Default SACL Access Right Weakness
BID:11387
Info
Microsoft Windows 2003 Services Default SACL Access Right Weakness
| Bugtraq ID: | 11387 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 12 2004 12:00AM |
| Updated: | Oct 12 2004 12:00AM |
| Credit: | Discovery of this weakness is credited to "Ziots, Edward" <[email protected]>, further research and corrections were submitted by Jean-Baptiste Marchand <[email protected]>. |
| Vulnerable: |
Microsoft Windows Server 2003 Web Edition SP1 Beta 1 Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard Edition SP1 Beta 1 Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Beta 1 Microsoft Windows Server 2003 Enterprise Edition Itanium 0 Microsoft Windows Server 2003 Enterprise Edition SP1 Beta 1 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Beta 1 Microsoft Windows Server 2003 Datacenter Edition Itanium 0 Microsoft Windows Server 2003 Datacenter Edition SP1 Beta 1 Microsoft Windows Server 2003 Datacenter Edition |
| Not Vulnerable: | |
Discussion
Microsoft Windows 2003 Services Default SACL Access Right Weakness
It is reported that the default SACL access right settings for multiple Microsoft Windows 2003 services are weak.
Reports indicate that several services have lax permissions that will allow unprivileged local users to start them.
Because any user can start these services, an administrator may be under a false sense of security.
It is reported that the default SACL access right settings for multiple Microsoft Windows 2003 services are weak.
Reports indicate that several services have lax permissions that will allow unprivileged local users to start them.
Because any user can start these services, an administrator may be under a false sense of security.
Exploit / POC
Microsoft Windows 2003 Services Default SACL Access Right Weakness
There is no exploit required.
There is no exploit required.
Solution / Fix
Microsoft Windows 2003 Services Default SACL Access Right Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Windows 2003 Services Default SACL Access Right Weakness
References:
References:
- Technet Security (Microsoft)
- Insecure Default Service DACL's in Windows 2003 ("Ziots, Edward"
) - Re: Insecure Default Service DACL's in Windows 2003 (Jean-Baptiste Marchand
)