Microsoft Windows XP Weak Default Configuration Vulnerability
BID:11410
Info
Microsoft Windows XP Weak Default Configuration Vulnerability
| Bugtraq ID: | 11410 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 13 2004 12:00AM |
| Updated: | Oct 13 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to <[email protected]>. |
| Vulnerable: |
Microsoft Windows XP Professional SP2 Microsoft Windows XP Media Center Edition SP2 Microsoft Windows XP Home SP2 |
| Not Vulnerable: | |
Discussion
Microsoft Windows XP Weak Default Configuration Vulnerability
Microsoft Windows XP Service Pack 2 is reported prone to a weak default configuration vulnerability. Internet Connection Firewall (ICF) includes functionality that controls what binaries are permitted to listen for incoming connections.
It is reported that one of the executables that is permitted to listen for incoming network connections may provide a conduit to bypass ICF access controls. Due to a configuration weakness, this executable is accessible for all users.
A local attacker may exploit this vulnerability to create a listening port to provide remote access to a vulnerable computer.
Microsoft Windows XP Service Pack 2 is reported prone to a weak default configuration vulnerability. Internet Connection Firewall (ICF) includes functionality that controls what binaries are permitted to listen for incoming connections.
It is reported that one of the executables that is permitted to listen for incoming network connections may provide a conduit to bypass ICF access controls. Due to a configuration weakness, this executable is accessible for all users.
A local attacker may exploit this vulnerability to create a listening port to provide remote access to a vulnerable computer.
Exploit / POC
Microsoft Windows XP Weak Default Configuration Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
Microsoft Windows XP Weak Default Configuration Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Windows XP Weak Default Configuration Vulnerability
References:
References: