Overview
The Microsoft Exchange System Attendant sets the permissions on a registry key incorrectly, allowing remote intruders access to the registry.
Description
The Microsoft Exchange System Attendant changes the permissions of the key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurePipeServers\winreg |
Impact
A remote intruder may be able to query or set registry key values remotely. The ACLs on the registry keys are still enforced correctly, but the ability for users to access the registry remotely may be undesired. If registry keys have weak permissions, data may be accidentally read or written. |
Solution
Apply a Patch |
Block Access to the Registry by Restricting SMB Network Access
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
The CERT/CC was made aware of this vulnerability by Microsoft Security Bulletin MS02-003.
This document was written by Cory F. Cohen.
Other Information
CVE IDs: | CVE-2002-0049 |
Severity Metric: | 4.62 |
Date Public: | 2002-02-07 |
Date First Published: | 2002-09-27 |
Date Last Updated: | 2003-03-26 20:47 UTC |
Document Revision: | 10 |