Microsoft Windows User Profile Privilege Escalation Vulnerability
BID:19375
CVE-2006-3443 |Info
Microsoft Windows User Profile Privilege Escalation Vulnerability
| Bugtraq ID: | 19375 |
| Class: | Design Error |
| CVE: |
CVE-2006-3443 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 08 2006 12:00AM |
| Updated: | Aug 24 2006 05:14PM |
| Credit: | Discovery is credited to Reed Arvin. |
| Vulnerable: |
Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows User Profile Privilege Escalation Vulnerability
Microsoft Windows is prone to a local privilege-escalation vulnerability. The vulnerability is caused by an insecure search path for the WinLogon facility. If exploited, this could let an attacker run an arbitrary DLL with elevated privileges.
This issue is reported to affect Windows 2000 in the default configuration. Other Windows operating systems are not affected unless the configuration settings related to this vulnerability are changed from the default.
Microsoft Windows is prone to a local privilege-escalation vulnerability. The vulnerability is caused by an insecure search path for the WinLogon facility. If exploited, this could let an attacker run an arbitrary DLL with elevated privileges.
This issue is reported to affect Windows 2000 in the default configuration. Other Windows operating systems are not affected unless the configuration settings related to this vulnerability are changed from the default.
Exploit / POC
Microsoft Windows User Profile Privilege Escalation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Microsoft Windows User Profile Privilege Escalation Vulnerability
Solution:
Microsoft has released a security bulletin to address this issue. Please refer to the attached security bulletin for details.
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows 2000 Professional SP4
Microsoft Windows 2000 Datacenter Server SP4
Solution:
Microsoft has released a security bulletin to address this issue. Please refer to the attached security bulletin for details.
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Security Update for Windows 2000 (KB917422)
http://www.microsoft.com/downloads/details.aspx?familyid=83e0c6fb-a542 -463a-88fd-dc388605a8ae&displaylang=en
Microsoft Windows 2000 Professional SP4
-
Microsoft Security Update for Windows 2000 (KB917422)
http://www.microsoft.com/downloads/details.aspx?familyid=83e0c6fb-a542 -463a-88fd-dc388605a8ae&displaylang=en
Microsoft Windows 2000 Datacenter Server SP4
-
Microsoft Security Update for Windows 2000 (KB917422)
http://www.microsoft.com/downloads/details.aspx?familyid=83e0c6fb-a542 -463a-88fd-dc388605a8ae&displaylang=en
References
Microsoft Windows User Profile Privilege Escalation Vulnerability
References:
References:
- Microsoft Security Bulletin MS06-051 (Microsoft)