OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[sec-adv] Windows 2000 Utility Manager Privilege Escalation Vulnerability

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Wed Jul 09 2003 - 13:50:56 CDT


TITLE:
Windows 2000 Utility Manager Privilege Escalation Vulnerability

READ ONLINE:
http://www.secunia.com/advisories/9224/

CRITICAL:
Less critical

IMPACT:
Privilege escalation

WHERE:
Local system

OPERATING SYSTEM:
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Server
Microsoft Windows 2000 Advanced Server
Microsoft Windows 2000 Datacenter Server

DESCRIPTION:
A vulnerability has been identified in Windows 2000, which can be
exploited by malicious, local users to escalate their privileges on a
vulnerable system.

The vulnerability is caused due to a validation error in the way the
Utility Manager handles Windows messages. This can be exploited by
running a specially crafted program, which sends a special Windows
message to the Utility Manager allowing arbitrary code to be run with
escalated privileges.

Successful exploitation grants Local System privileges to the
malicious user.

SOLUTION:
Apply patch or Service Pack 4.

Patch (requires SP3 installed):
http://microsoft.com/downloads/details.aspx?FamilyId=D415A4AC-E13A-4E8A-BE25-85E7DF686F61&displaylang=en

Service Pack 4:
http://www.microsoft.com/windows2000/downloads/servicepacks/sp4/default.asp

REPORTED BY / CREDITS:
Chris Paget (Next Generation Security Software).

ORIGINAL ADVISORY:
http://www.microsoft.com/technet/security/bulletin/MS03-025.asp

OTHER REFERENCES:
http://www.nextgenss.com/advisories/utilitymanager.txt

----------------------------------------------------------------------

Secunia recommends that you verify all advisories you receive, by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

Contact details:
Web : http://www.secunia.com/
E-mail : supportsecunia.com
Tel : +44 (0) 20 7016 2693
Fax : +44 (0) 20 7637 0419

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------