Microsoft Windows NT Security Policy Bypass Vulnerability
BID:4236
Info
Microsoft Windows NT Security Policy Bypass Vulnerability
| Bugtraq ID: | 4236 |
| Class: | Design Error |
| CVE: |
CVE-2002-0421 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 06 2002 12:00AM |
| Updated: | Jul 11 2009 10:56AM |
| Credit: | Reported by Syed Mohamed A <[email protected]>. |
| Vulnerable: |
Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows NT Security Policy Bypass Vulnerability
Microsoft IIS is a popular web server package for Windows NT based platforms. Version 4.0 of IIS installs a remotely accessible directory, /IISADMPWD, which contains a number of vulnerable .HTR files. These are designed to allow system administrators the ability to provide HTTP based password change services to network users. Requesting one of the .htr files returns a form that requests the account name, current password, and changed password.
An issue has been reported which could allow NT users, with their local security policy set to "User cannot change password", to change their password via IISADMPWD.
Microsoft IIS is a popular web server package for Windows NT based platforms. Version 4.0 of IIS installs a remotely accessible directory, /IISADMPWD, which contains a number of vulnerable .HTR files. These are designed to allow system administrators the ability to provide HTTP based password change services to network users. Requesting one of the .htr files returns a form that requests the account name, current password, and changed password.
An issue has been reported which could allow NT users, with their local security policy set to "User cannot change password", to change their password via IISADMPWD.
Exploit / POC
Microsoft Windows NT Security Policy Bypass Vulnerability
No exploit code required.
No exploit code required.
Solution / Fix
Microsoft Windows NT Security Policy Bypass Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Windows NT Security Policy Bypass Vulnerability
References:
References: