NT RASMAN Privilege Escalation Vulnerability
BID:645
Info
NT RASMAN Privilege Escalation Vulnerability
| Bugtraq ID: | 645 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Sep 17 1999 12:00AM |
| Updated: | Sep 17 1999 12:00AM |
| Credit: | This vulnerability was posted to the NTBugtraq mailing list by Alberto Rodríguez Aragonés <[email protected]>. |
| Vulnerable: |
Microsoft Windows NT 4.0 SP5 Microsoft Windows NT 4.0 SP4 Microsoft Windows NT 4.0 SP3 Microsoft Windows NT 4.0 SP2 Microsoft Windows NT 4.0 SP1 Microsoft Windows NT 4.0 |
| Not Vulnerable: | |
Discussion
NT RASMAN Privilege Escalation Vulnerability
Any authenticated NT user (ie domain user) can modify the pathname for the RASMAN binary in the Registry. The next time the RAS Service is started, the (trojan) service referenced by the RASMAN pathname will be executed with system privileges. This trojan service may allow the User to execute commands on the target server as an administrator, including elevating the privileges of their own account to that of Administrator. A modified (UNC) pathname may be used to point to an executable existing on another host on the network.
Any authenticated NT user (ie domain user) can modify the pathname for the RASMAN binary in the Registry. The next time the RAS Service is started, the (trojan) service referenced by the RASMAN pathname will be executed with system privileges. This trojan service may allow the User to execute commands on the target server as an administrator, including elevating the privileges of their own account to that of Administrator. A modified (UNC) pathname may be used to point to an executable existing on another host on the network.
Solution / Fix
NT RASMAN Privilege Escalation Vulnerability
Solution:
Microsoft has released a tool that will set proper permissions over the HKEY_Local_Machine/SYSTEM/CurrentControlSet/Services/RASMan key
The Post SP6 Rasman-fix tool can be downloaded from ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/nt40/Hotfixes-PostSP6/Security/Rasman-fix/
This tool may be executed against any NT host, regardless of the current Service Pack level. The tool may be executed against a remote machine using the syntax: "fixrasi \\machinename" (without the quotes).
Solution:
Microsoft has released a tool that will set proper permissions over the HKEY_Local_Machine/SYSTEM/CurrentControlSet/Services/RASMan key
The Post SP6 Rasman-fix tool can be downloaded from ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/nt40/Hotfixes-PostSP6/Security/Rasman-fix/
This tool may be executed against any NT host, regardless of the current Service Pack level. The tool may be executed against a remote machine using the syntax: "fixrasi \\machinename" (without the quotes).
References
NT RASMAN Privilege Escalation Vulnerability
References:
References: