Infesting you with Virus News
 

Vulnerabilities

Incorrect ACLs on Windows services allow privilege escalation (PC1-2006-0077)

Overview

Vulnerability chart

Overview: N/A
Vulnerable:
Windows Server 2003
Windows XP
Unknown vulnerability
Unknown patch
availability
Patch implementation
unknown

References to Advisories, Solutions, and Tools

Release date: 2006-02-08
Content:
===========================================================================
AA-2006.0013                  AUSCERT Advisory

                                   [Win]
       Incorrect ACLs on Windows services allow privilege escalation
                              8 February 2006
- ---------------------------------------------------------------------------

        AusCERT Advisory Summary
        ------------------------

Product:           Windows XP SP1
                   Windows Server 2003
                   Unspecified third-party Windows services
Operating System:  Windows
Impact:            Increased Privileges
Access:            Existing Account
CVE Names:         CVE-2006-0023
Member-only until: Friday, February 10 2006


OVERVIEW:

	Windows XP prior to Service Pack 2 provides incorrect access controls 
	on four Windows services. Two of these (UPnP and SSDP) can be exploited
	by unprivileged authenticated users. By changing a service's binary 
	path a user can execute arbitrary code with increased privileges.

	On Windows Server 2003 prior to Service Pack 1 the problem affects 
	one service (NetBT) but is only exploitable by users in the Network
	Configuration Operators group.

	Microsoft Security Advisory 914457 has been released, describing these
	vulnerabilities. [1] 

	Microsoft reports that some third-party products that install a service 
	may also be affected.
	

IMPACT:

	Any authenticated user on the vulnerable Windows XP system can execute 
	arbitrary code with increased privileges.


MITIGATION:

	Installing Windows XP Service Pack 2 or Windows Server 2003 Service
	Pack 1 fixes these vulnerabilities.

	Microsoft's advisory includes steps for manually fixing the permissions 
	on the affected services, as well as using Group Policy to deploy the
	access control changes to Windows XP SP1 systems.


REFERENCES:

	[1] Microsoft Security Advisory 914457
	    http://www.microsoft.com/technet/security/advisory/914457.mspx


AusCERT has made every effort to ensure that the information contained
in this document is accurate.  However, the decision to use the information
described is the responsibility of each user or organisation. The decision to
follow or act on information or advice contained in this security bulletin is
the responsibility of each user or organisation, and should be considered in
accordance with your organisation's site policies and procedures. AusCERT
takes no responsibility for consequences which may arise from following or
acting on information or advice contained in this security bulletin.

If you believe that your computer system has been compromised or attacked in 
any way, we encourage you to let us know by completing the secure National IT 
Incident Reporting Form at:

        http://www.auscert.org.au/render.html?it=3192

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================

Security Bulletin Summary

Products: Windows XP SP1
Risk level
  • Low
  • Medium
  • High
  • Extreme
  • Severe
Warning: security vulnerability level = severe
129 vulnerabilities(-y) found between 20 December, 2001 and 14 May, 2013.
Windows XP refers to a line of operating systems developed by Microsoft for... more
4916 files found: osk.exe, migwiz.exe, tlntadmn.exe, SYSPARSE.EXE, exctrlst.exe, tsprof.exe, xrxftplt.exe, nslookup.exe, oschoice.exe, dmdiag.exe, qprocess.exe, EXCH_regtrace.exe, cipher.exe, logman.exe, gprslt.exe... more

Windows Server 2003
Risk level
  • Low
  • Medium
  • High
  • Extreme
  • Severe
Warning: security vulnerability level = severe
51 vulnerabilities(-y) found between 10 July, 2003 and 14 July, 2009.
Windows Server 2003 (known as Win2K3) points to a server operating system... more
512 files found: owsadm.exe, w3wp.exe, httpcfg.exe, wmseditor.exe, dsrm.exe, IEExec.exe, dcgpofix.exe, portqry.exe, msppcnfg.exe, cmdkey.exe, addusr.exe, tapicfg.exe, dsget.exe, dsadd.exe, pop3svc.exe... more

Unspecified third-party Windows services
Operating Systems: Windows
Impact:Increased Privileges

Say something interesting!

Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Home > Vulnerabilities > PC1-2006-0077