Microsoft Windows Terminal Server Group Policy Bypass Vulnerability
BID:4464
Info
Microsoft Windows Terminal Server Group Policy Bypass Vulnerability
| Bugtraq ID: | 4464 |
| Class: | Design Error |
| CVE: |
CVE-2002-0444 |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 09 2002 12:00AM |
| Updated: | Jul 11 2009 11:56AM |
| Credit: | Discovered by [email protected] <[email protected]>. |
| Vulnerable: |
Microsoft Windows 2000 Terminal Services SP2 Microsoft Windows 2000 Terminal Services SP1 Microsoft Windows 2000 Terminal Services |
| Not Vulnerable: | |
Discussion
Microsoft Windows Terminal Server Group Policy Bypass Vulnerability
An issue has been reported in Microsoft Windows Terminal Server, which could allow a user of the service to bypass the group policy setting and access restricted resources.
Reportedly, when per server licensing is set for a specific number of users, and the number of permitted users has been exceeded, a connection to the SYSVOL share to inherit appropriate group policy settings fails. Therefore, legitimate users can peruse various resources on the host with his/her user permissions.
An issue has been reported in Microsoft Windows Terminal Server, which could allow a user of the service to bypass the group policy setting and access restricted resources.
Reportedly, when per server licensing is set for a specific number of users, and the number of permitted users has been exceeded, a connection to the SYSVOL share to inherit appropriate group policy settings fails. Therefore, legitimate users can peruse various resources on the host with his/her user permissions.
Exploit / POC
Microsoft Windows Terminal Server Group Policy Bypass Vulnerability
No exploit code required.
No exploit code required.
References
Microsoft Windows Terminal Server Group Policy Bypass Vulnerability
References:
References: