Microsoft SMS 2.0 Default Permissions Vulnerability
BID:945
Info
Microsoft SMS 2.0 Default Permissions Vulnerability
| Bugtraq ID: | 945 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 29 1999 12:00AM |
| Updated: | Dec 29 1999 12:00AM |
| Credit: | Posted to the Win2kSecAdvice mailing list on Dec 29, 1999 by Frank Monroe <[email protected]>. |
| Vulnerable: |
Microsoft Systems Management Server 2.0 |
| Not Vulnerable: | |
Exploit / POC
Microsoft SMS 2.0 Default Permissions Vulnerability
Replace %SMS_LOCAL_DIR%\MS\SMS\CLICOMP\REMCTRL\WUSER32.EXE with a copy of wuser32.exe. After the next reboot, User Manager will run at startup with System privileges, allowing the logged-in user to add their account to arbitrary groups, including Administrators.
Replace %SMS_LOCAL_DIR%\MS\SMS\CLICOMP\REMCTRL\WUSER32.EXE with a copy of wuser32.exe. After the next reboot, User Manager will run at startup with System privileges, allowing the logged-in user to add their account to arbitrary groups, including Administrators.
Solution / Fix
Microsoft SMS 2.0 Default Permissions Vulnerability
Solution:
Microsoft has released a patch for this issue, available at:
Intel: http://www.microsoft.com/Downloads/Release.asp?ReleaseID=18498
Alpha: http://www.microsoft.com/Downloads/Release.asp?ReleaseID=18499
Solution:
Microsoft has released a patch for this issue, available at:
Intel: http://www.microsoft.com/Downloads/Release.asp?ReleaseID=18498
Alpha: http://www.microsoft.com/Downloads/Release.asp?ReleaseID=18499
References
Microsoft SMS 2.0 Default Permissions Vulnerability
References:
References: