PT-2006-4331 · Microsoft · Windows 2000 Sp4+1
Reed Arvin
·
Publicado
2006-08-08
·
Atualizado
2019-04-30
·
CVE-2006-3443
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows 2000 SP4
Description
The issue is related to an untrusted search path vulnerability in Winlogon, which can be exploited when SafeDllSearchMode is disabled. This allows local users to gain privileges via a malicious DLL in the UserProfile directory. The vulnerability could enable a logged-on user to take complete control of the system.
Recommendations
For Microsoft Windows 2000 SP4, enable SafeDllSearchMode to prevent the exploitation of this issue.
As a temporary workaround, consider restricting access to the UserProfile directory to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Windows 2000 Sp4
Windows