NT Unattended Installation File Vulnerability
BID:626
Info
NT Unattended Installation File Vulnerability
| Bugtraq ID: | 626 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 10 1999 12:00AM |
| Updated: | Sep 10 1999 12:00AM |
| Credit: | Microsoft Security Bulletin MS99-036, released September 10, 1999. |
| Vulnerable: |
Microsoft Windows NT 4.0 |
| Not Vulnerable: | |
Discussion
NT Unattended Installation File Vulnerability
When an unattended installation of Windows NT4 is performed, the configuration details are read from the Unattend.txt file. The contents of this file are copied to one of two locations, depending on the type of installation: %windir%\system32\$winnt$.inf for a normal unattended installation, or %windir%\system32\$nt4pre$.inf for an installation using Sysprep. This file is not deleted after the installation, and can be read by any Interactive User. In certain circumstances, this file may include the administrative password in plain-text.
When an unattended installation of Windows NT4 is performed, the configuration details are read from the Unattend.txt file. The contents of this file are copied to one of two locations, depending on the type of installation: %windir%\system32\$winnt$.inf for a normal unattended installation, or %windir%\system32\$nt4pre$.inf for an installation using Sysprep. This file is not deleted after the installation, and can be read by any Interactive User. In certain circumstances, this file may include the administrative password in plain-text.
Exploit / POC
NT Unattended Installation File Vulnerability
see discussion
see discussion
Solution / Fix
NT Unattended Installation File Vulnerability
Solution:
Microsoft suggests that this file be deleted.
Solution:
Microsoft suggests that this file be deleted.
References
NT Unattended Installation File Vulnerability
References:
References: