Microsoft LSASS ADAM/ADLDS Privilege Escalation Vulnerability
BID:43037
Info
Microsoft LSASS ADAM/ADLDS Privilege Escalation Vulnerability
| Bugtraq ID: | 43037 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-0820 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 14 2010 12:00AM |
| Updated: | Oct 15 2010 04:49PM |
| Credit: | Microsoft |
| Vulnerable: |
Microsoft Active Directory Lightweight Directory Service 0 Microsoft Active Directory Application Mode (ADAM) 0 Microsoft Active Directory 0 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Webportal 0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 Avaya CallPilot Unified Messaging 0 Avaya Aura Conferencing 6.0 Standard |
| Not Vulnerable: | |
Discussion
Microsoft LSASS ADAM/ADLDS Privilege Escalation Vulnerability
Microsoft Windows Local Security Authority Subsystem Service (LSASS) is prone to a privilege-escalation vulnerability. This issue occurs in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (ADLDS).
An attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successfully exploiting this issue will facilitate in the complete compromise of affected computers.
Microsoft Windows Local Security Authority Subsystem Service (LSASS) is prone to a privilege-escalation vulnerability. This issue occurs in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (ADLDS).
An attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successfully exploiting this issue will facilitate in the complete compromise of affected computers.
Exploit / POC
Microsoft LSASS ADAM/ADLDS Privilege Escalation Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft LSASS ADAM/ADLDS Privilege Escalation Vulnerability
Solution:
Microsoft has released patches and an advisory to address this issue. Please see the references for more information.
Microsoft Active Directory Lightweight Directory Service 0
Microsoft Active Directory Application Mode (ADAM) 0
Solution:
Microsoft has released patches and an advisory to address this issue. Please see the references for more information.
Microsoft Active Directory Lightweight Directory Service 0
-
Microsoft Security Update for Windows 7 (KB981550)
http://www.microsoft.com/downloads/en/details.aspx?familyid=454FC025-B FA2-4552-9522-3585F523ECB2&displaylang=en -
Microsoft Security Update for Windows Server 2008 R2 x64 Edition (KB981550)
http://www.microsoft.com/downloads/en/details.aspx?familyid=54F36389-8 BE4-4A0C-9640-DC32ADDAC9D7&displaylang=en -
Microsoft Security Update for Windows Vista (KB981550)
http://www.microsoft.com/downloads/en/details.aspx?familyid=853A71F3-F B0D-43AF-A2B8-45BF8CA1A588&displaylang=en -
Microsoft Security Update for Windows Server 2008 (KB981550)
http://www.microsoft.com/downloads/en/details.aspx?familyid=1452BEFE-B 7B8-4131-B36F-DDED2BD16D5E&displaylang=en -
Microsoft Security Update for Windows Server 2008 x64 Edition (KB981550)
http://www.microsoft.com/downloads/en/details.aspx?familyid=38EB875F-1 869-401B-B7D3-9F18F4BA4F24&displaylang=en -
Microsoft Security Update for Windows 7 for x64-based Systems (KB981550)
http://www.microsoft.com/downloads/en/details.aspx?familyid=454FC025-B FA2-4552-9522-3585F523ECB2&displaylang=en -
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB981550)
http://www.microsoft.com/downloads/en/details.aspx?familyid=853A71F3-F B0D-43AF-A2B8-45BF8CA1A588&displaylang=en -
Microsoft Security Update for Windows Vista for x64-based Systems (KB981550)
http://www.microsoft.com/downloads/en/details.aspx?familyid=566F468B-2 2B6-400A-A656-AE64CFCB52DF&displaylang=en
Microsoft Active Directory Application Mode (ADAM) 0
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB981550)
http://www.microsoft.com/downloads/en/details.aspx?familyid=5BC00F9A-3 028-4C9D-BE06-F2B78FA444C4&displaylang=en -
Microsoft Security Update for Windows Server 2003 (KB982000)
http://www.microsoft.com/downloads/details.aspx?familyid=C42731F1-6393 -42ED-B59F-5310C832FDC4 -
Microsoft Security Update for Windows Server 2003 x64 Edition (KB982000)
http://www.microsoft.com/downloads/en/details.aspx?familyid=79FB639D-2 CC1-4BEA-9DF6-C67ED95890E3&displaylang=en -
Microsoft Security Update for Windows Server 2003 (KB981550)
http://www.microsoft.com/downloads/en/details.aspx?familyid=3FE6E78C-C 60A-4903-9273-27B37E129F0A&displaylang=en -
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB981550)
http://www.microsoft.com/downloads/details.aspx?familyid=CAB75C8A-0D12 -4A91-82B2-9F9B70610F67 -
Microsoft Security Update for Windows XP (KB982000)
http://www.microsoft.com/downloads/details.aspx?familyid=6554F98F-4DC5 -4784-B92C-B0AAE1FA22CA -
Microsoft Security Update for Windows XP x64 Edition (KB982000)
http://www.microsoft.com/downloads/en/details.aspx?familyid=5BC00F9A-3 028-4C9D-BE06-F2B78FA444C4&displaylang=en
References
Microsoft LSASS ADAM/ADLDS Privilege Escalation Vulnerability
References:
References: