Overview
Microsoft Windows access controls may be improperly configured potentially allowing a local attacker to gain elevated privileges on a vulnerable system.
Description
Microsoft Windows provides numerous, fine grained permissions and privileges to control access to Windows components, such as services, files, and registry entries. Recent research has uncovered insecure configurations within user accounts and groups on Microsoft Windows systems. These configurations may allow local attackers to gain access to, and manipulate system resources. The researchers have developed a model that analyzes permissions to expose privilege escalation vulnerabilities. The research focused on three particular components of the Windows architecture:
|
Impact
A local user with valid login credentials may be able gain elevated privileges on a vulnerable Windows system. |
Solution
These issues are corrected in Service Pack 2 for Microsoft Windows XP and Service Pack 1 for Microsoft Windows Server 2003. In addition, Microsoft Security Advisory 914457 and Microsoft Security Bulletin MS06-011 contain numerous workarounds to mitigate these vulnerabilities. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.microsoft.com/technet/security/advisory/914457.mspx
- http://www.microsoft.com/technet/security/Bulletin/MS06-011.mspx
- http://msdn.microsoft.com/library/default.asp?url=/library/en-us/fileio/fs/file_security_and_access_rights.asp
- http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dllproc/base/service_security_and_access_rights.asp
- http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf
- http://support.microsoft.com/?id=914392
Acknowledgements
These vulnerabilities were reported by Sudhakar Govindavajhala and Andrew W. Appel.
This document was written by Jeff Gennari.
Other Information
CVE IDs: | CVE-2006-0023 |
Severity Metric: | 4.22 |
Date Public: | 2006-01-31 |
Date First Published: | 2006-02-08 |
Date Last Updated: | 2006-04-21 21:58 UTC |
Document Revision: | 69 |