Microsoft Windows Active Directory Policy Bypass Vulnerability
BID:7330
Info
Microsoft Windows Active Directory Policy Bypass Vulnerability
| Bugtraq ID: | 7330 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 11 2003 12:00AM |
| Updated: | Apr 11 2003 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Rickard Berglind <[email protected]>. |
| Vulnerable: |
Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows Active Directory Policy Bypass Vulnerability
The vulnerability is related to the way DCs handle the task of managing the Schema and Configuration partitions.
Exploitation of this vulnerability will result in attackers being able to manipulate the Schema and Configuration partitions on other DCs. This has the potential to cause serious network problems for an existing Windows domain.
Malicious administrators, through the use of weak permissions, are able to execute certain services under the SYSTEM context to manipulate the contents of the Schema and Configuration partitions.
The vulnerability is related to the way DCs handle the task of managing the Schema and Configuration partitions.
Exploitation of this vulnerability will result in attackers being able to manipulate the Schema and Configuration partitions on other DCs. This has the potential to cause serious network problems for an existing Windows domain.
Malicious administrators, through the use of weak permissions, are able to execute certain services under the SYSTEM context to manipulate the contents of the Schema and Configuration partitions.
Exploit / POC
Microsoft Windows Active Directory Policy Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Windows Active Directory Policy Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Windows Active Directory Policy Bypass Vulnerability
References:
References:
- AD Schema and Configuration could be overtaken (Rickard Berglind
)