NT IBM Netfinity Remote Control Software Vulnerability
BID:284
Info
NT IBM Netfinity Remote Control Software Vulnerability
| Bugtraq ID: | 284 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 10 1999 12:00AM |
| Updated: | May 10 1999 12:00AM |
| Credit: | This vulnerability was identified by Thomas Krug <[email protected]> and was posted to NTBugtraq by Russ Cooper. NOTE: Althought the vulnerability was posted to NTBugtraq by Russ Cooper, Russ was not responsible for idenitfying the vulnerability. |
| Vulnerable: |
IBM Remote Control Software 1.0 |
| Not Vulnerable: | |
Discussion
NT IBM Netfinity Remote Control Software Vulnerability
The IBM Remote Control Software package requires a client module to be loaded on NT hosts to be remotey controlled. This client module is loaded as an NT service and must run under either the local system account or the user context of a user account having administrative privileges.
It has been discovered that this service may be exploited by a local user level account to execute code with administrator privileges. This vulnerability would allow a user (with no admin rights) to execute programs that might allow them to elevate their privileges to that of an administrator.
The IBM Remote Control Software package requires a client module to be loaded on NT hosts to be remotey controlled. This client module is loaded as an NT service and must run under either the local system account or the user context of a user account having administrative privileges.
It has been discovered that this service may be exploited by a local user level account to execute code with administrator privileges. This vulnerability would allow a user (with no admin rights) to execute programs that might allow them to elevate their privileges to that of an administrator.
Exploit / POC
NT IBM Netfinity Remote Control Software Vulnerability
Open the Netfinity client. Launch the Process Manager. From the Process Manager interface, launch arbitrary code. usrmgr.exe, musrmgr.exe, regedt32.exe, etc. may be launched and be used by the user level account to grant administrator privileges to any account on the host (or domain).
Open the Netfinity client. Launch the Process Manager. From the Process Manager interface, launch arbitrary code. usrmgr.exe, musrmgr.exe, regedt32.exe, etc. may be launched and be used by the user level account to grant administrator privileges to any account on the host (or domain).
Solution / Fix
NT IBM Netfinity Remote Control Software Vulnerability
Solution:
Do not run the IBM Remote Control Software application or client modules on your NT hosts.
IBM will be releasing a patch for this vulnerability. In the meantime, IBM suggests:
Set NTFS LIST permissions over the WNETFIN directory. This will prevent users from executing the Netfinity Manager Services.
Use Netfinity Security Manager to restrict access to Process Manager and Remote Session.
Configure the Netfinity Manager Services to start with a non-administrator level user account.
Audit the activities of the service-user account.
Do not install Netfinity Manager Services on client machines. Only install Client Services for Netfinity Manager on client machines.
Prevent the installation of Process Manager and Remote Session by editing the INSTALL.INI file.
Solution:
Do not run the IBM Remote Control Software application or client modules on your NT hosts.
IBM will be releasing a patch for this vulnerability. In the meantime, IBM suggests:
Set NTFS LIST permissions over the WNETFIN directory. This will prevent users from executing the Netfinity Manager Services.
Use Netfinity Security Manager to restrict access to Process Manager and Remote Session.
Configure the Netfinity Manager Services to start with a non-administrator level user account.
Audit the activities of the service-user account.
Do not install Netfinity Manager Services on client machines. Only install Client Services for Netfinity Manager on client machines.
Prevent the installation of Process Manager and Remote Session by editing the INSTALL.INI file.
References
NT IBM Netfinity Remote Control Software Vulnerability
References:
References: