Network Instruments NIPrint LDP-LPR Privilege Escalation Vulnerability
BID:8969
Info
Network Instruments NIPrint LDP-LPR Privilege Escalation Vulnerability
| Bugtraq ID: | 8969 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 03 2003 12:00AM |
| Updated: | Nov 03 2003 12:00AM |
| Credit: | Announced by KF <[email protected]>. |
| Vulnerable: |
Network Instruments NIPrint LPD-LPR Print Server 4.10 |
| Not Vulnerable: | |
Discussion
Network Instruments NIPrint LDP-LPR Privilege Escalation Vulnerability
NIPrint runs as a service, with SYSTEM privileges, by default. It is accessible to all users locally through an icon in the taskbar. According to the report, the "help" system used by NIPrint can invoke Explorer as SYSTEM. An attacker can, in turn, use Explorer to run commands with administrative privileges.
This vulnerability may be an instance of the general issue described in BID 8884.
NIPrint runs as a service, with SYSTEM privileges, by default. It is accessible to all users locally through an icon in the taskbar. According to the report, the "help" system used by NIPrint can invoke Explorer as SYSTEM. An attacker can, in turn, use Explorer to run commands with administrative privileges.
This vulnerability may be an instance of the general issue described in BID 8884.
Exploit / POC
Network Instruments NIPrint LDP-LPR Privilege Escalation Vulnerability
Exploit contributed by Crazy Einstein.
Exploit contributed by Crazy Einstein.
Solution / Fix
Network Instruments NIPrint LDP-LPR Privilege Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.