NT Clipboard Available To Unauthenticated Users Vulnerability
BID:198
Info
NT Clipboard Available To Unauthenticated Users Vulnerability
| Bugtraq ID: | 198 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 29 1999 12:00AM |
| Updated: | Jan 29 1999 12:00AM |
| Credit: | This vulnerability was posted to the NTBugtraq mailing list by David Reed <[email protected]> |
| Vulnerable: |
Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT 3.5.1 SP5 Microsoft Windows NT 3.5.1 SP4 Microsoft Windows NT 3.5.1 SP3 Microsoft Windows NT 3.5.1 SP2 Microsoft Windows NT 3.5.1 SP1 Microsoft Windows NT 4.0 SP4 Microsoft Windows NT 4.0 SP3 Microsoft Windows NT 4.0 SP2 Microsoft Windows NT 4.0 SP1 Microsoft Windows NT 4.0 |
| Not Vulnerable: | |
Discussion
NT Clipboard Available To Unauthenticated Users Vulnerability
Users may paste information to the Windows clipboard in a variety of ways: CTL-C, edit cut, edit copy, etc. This information remains in the clipboard until it is maually cleared or the machine is shutdown.
When a user secures his or her desktop by pressing ctl-alt-del then enter, or when a password protected screensaver becomes active, the user assumes their host and their data to be secure from access at the local console.
Data stored in the clipboard can still be accessed even thought the console is locked. Pressing ctl-alt-del will invoke the logon window. Instead of typing the users name, the clipboard data can be displayed by pressing ctl-v while the cursor is in the username or password window.
Jason Adam Young <[email protected]> posted to NTBugtraq and expressed concern that Microsoft may not have fixed the problem by simply releasing an update GINA. Instead, he feels that the problem lies within the Clipboard and its interaction with the WindowStation system object.
Users may paste information to the Windows clipboard in a variety of ways: CTL-C, edit cut, edit copy, etc. This information remains in the clipboard until it is maually cleared or the machine is shutdown.
When a user secures his or her desktop by pressing ctl-alt-del then enter, or when a password protected screensaver becomes active, the user assumes their host and their data to be secure from access at the local console.
Data stored in the clipboard can still be accessed even thought the console is locked. Pressing ctl-alt-del will invoke the logon window. Instead of typing the users name, the clipboard data can be displayed by pressing ctl-v while the cursor is in the username or password window.
Jason Adam Young <[email protected]> posted to NTBugtraq and expressed concern that Microsoft may not have fixed the problem by simply releasing an update GINA. Instead, he feels that the problem lies within the Clipboard and its interaction with the WindowStation system object.
Exploit / POC
NT Clipboard Available To Unauthenticated Users Vulnerability
See discussion.
See discussion.
Solution / Fix
NT Clipboard Available To Unauthenticated Users Vulnerability
Solution:
Microsoft has issued Post SP3 and Post SP4 hotfixes for this vulnerability:
Post SP3 - ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/NT40/hotfixes-postSP3/Gina-fix/
Post SP4 - ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/NT40/hotfixes-postSP4/Gina-fix/
Refer to the Microsoft Q article for further information on this fix: http://support.microsoft.com/support/kb/articles/q214/8/02.asp
Solution:
Microsoft has issued Post SP3 and Post SP4 hotfixes for this vulnerability:
Post SP3 - ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/NT40/hotfixes-postSP3/Gina-fix/
Post SP4 - ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/NT40/hotfixes-postSP4/Gina-fix/
Refer to the Microsoft Q article for further information on this fix: http://support.microsoft.com/support/kb/articles/q214/8/02.asp
References
NT Clipboard Available To Unauthenticated Users Vulnerability
References:
References: