Microsoft Windows NT Dr. Watson 'user.dmp' Permissions Vulnerability
BID:2501
Info
Microsoft Windows NT Dr. Watson 'user.dmp' Permissions Vulnerability
| Bugtraq ID: | 2501 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Mar 23 2001 12:00AM |
| Updated: | Mar 23 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq by Craig Boston <[email protected]> on March 23, 2001. |
| Vulnerable: |
Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Workstation 4.0 SP6 Microsoft Windows NT Workstation 4.0 SP5 Microsoft Windows NT Workstation 4.0 SP4 Microsoft Windows NT Workstation 4.0 SP3 Microsoft Windows NT Workstation 4.0 SP2 Microsoft Windows NT Workstation 4.0 SP1 Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows NT Dr. Watson 'user.dmp' Permissions Vulnerability
Due to a flaw in Microsoft Windows NT's implementation of Dr. Watson, the Everyone group has Full Control of the crash dump file (user.dmp). The file contains program error details, including information on the computer and the user logged in at the time the error took place. If a user successfully gains access to this file, it is possible to obtain sensitive information, such as users' mail passwords or other private data.
Properly exploited, this information could lead to further compromises of the vulnerable system.
Due to a flaw in Microsoft Windows NT's implementation of Dr. Watson, the Everyone group has Full Control of the crash dump file (user.dmp). The file contains program error details, including information on the computer and the user logged in at the time the error took place. If a user successfully gains access to this file, it is possible to obtain sensitive information, such as users' mail passwords or other private data.
Properly exploited, this information could lead to further compromises of the vulnerable system.
Exploit / POC
Microsoft Windows NT Dr. Watson 'user.dmp' Permissions Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Windows NT Dr. Watson 'user.dmp' Permissions Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Windows NT Dr. Watson 'user.dmp' Permissions Vulnerability
References:
References:
- PGP 7.x with Outlook will give your passphrase in CLEAR (Adonis.No.Spam
)