PT-2004-3620 · Sysinternals · Pssuspend+10
Published
2004-12-31
·
Updated
2017-07-29
·
CVE-2004-2730
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Sysinternals PsTools versions prior to 2.05
PsExec versions prior to 1.54
PsGetsid versions prior to 1.41
PsInfo versions prior to 1.61
PsKill versions prior to 1.03
PsList versions prior to 1.26
PsLoglist versions prior to 2.51
PsPasswd versions prior to 1.21
PsService versions prior to 2.12
PsSuspend versions prior to 1.05
PsShutdown versions prior to 2.32
Description
The issue allows local users to access remote IPC$ and ADMIN$ shares with elevated privileges by utilizing the existing share mapping, due to the software's failure to properly disconnect from these shares.
Recommendations
For PsTools version prior to 2.05, update to version 2.05 or later.
For PsExec version prior to 1.54, update to version 1.54 or later.
For PsGetsid version prior to 1.41, update to version 1.41 or later.
For PsInfo version prior to 1.61, update to version 1.61 or later.
For PsKill version prior to 1.03, update to version 1.03 or later.
For PsList version prior to 1.26, update to version 1.26 or later.
For PsLoglist version prior to 2.51, update to version 2.51 or later.
For PsPasswd version prior to 1.21, update to version 1.21 or later.
For PsService version prior to 2.12, update to version 2.12 or later.
For PsSuspend version prior to 1.05, update to version 1.05 or later.
For PsShutdown version prior to 2.32, update to version 2.32 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Psexec
Psgetsid
Psinfo
Pskill
Pslist
Psloglist
Pspasswd
Psservice
Psshutdown
Pssuspend
Pstools