PT-2001-1283 · Microsoft · Transaction Server+1
Published
2001-02-02
·
Updated
2018-10-12
·
CVE-2001-0047
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Windows NT 4.0
Description:
The issue concerns the default permissions for the MTS Package Administration registry key, which allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages. This could potentially lead to privilege escalation.
Recommendations:
For Windows NT 4.0, consider restricting access to the MTS Package Administration registry key to prevent local users from installing or modifying arbitrary MTS packages. As a temporary workaround, restrict privileges for local users to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Transaction Server
Windows Nt 4.0