PT-2010-4661 · Microsoft · Windows Server 2008 R2+1
Publicado
2010-10-13
·
Atualizado
2018-10-12
·
CVE-2010-3223
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Server 2008 R2
Description
A tampering issue exists due to improper handling of permissions on shared cluster disks by the Failover Cluster Manager user interface. The Failover Cluster Manager uses unsecured default permissions when adding disks to a cluster, potentially providing unauthorized users with read/write/delete access to the administrative shares on the failover cluster disk. This allows remote attackers to read or modify data on these disks via requests to the associated share.
Recommendations
For Microsoft Windows Server 2008 R2, consider restricting access to the administrative shares on the failover cluster disk to minimize the risk of exploitation. As a temporary workaround, review and manually set proper permissions on new cluster disks that are shared as part of a failover cluster. Ensure that only authorized users have access to these shares.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Windows Server 2008 R2
Windows