PT-2004-3620 · Sysinternals · Pssuspend+10

Published

2004-12-31

·

Updated

2017-07-29

·

CVE-2004-2730

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Sysinternals PsTools versions prior to 2.05 PsExec versions prior to 1.54 PsGetsid versions prior to 1.41 PsInfo versions prior to 1.61 PsKill versions prior to 1.03 PsList versions prior to 1.26 PsLoglist versions prior to 2.51 PsPasswd versions prior to 1.21 PsService versions prior to 2.12 PsSuspend versions prior to 1.05 PsShutdown versions prior to 2.32
Description The issue allows local users to access remote IPC$ and ADMIN$ shares with elevated privileges by utilizing the existing share mapping, due to the software's failure to properly disconnect from these shares.
Recommendations For PsTools version prior to 2.05, update to version 2.05 or later. For PsExec version prior to 1.54, update to version 1.54 or later. For PsGetsid version prior to 1.41, update to version 1.41 or later. For PsInfo version prior to 1.61, update to version 1.61 or later. For PsKill version prior to 1.03, update to version 1.03 or later. For PsList version prior to 1.26, update to version 1.26 or later. For PsLoglist version prior to 2.51, update to version 2.51 or later. For PsPasswd version prior to 1.21, update to version 1.21 or later. For PsService version prior to 2.12, update to version 2.12 or later. For PsSuspend version prior to 1.05, update to version 1.05 or later. For PsShutdown version prior to 2.32, update to version 2.32 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2004-2730

Affected Products

Psexec
Psgetsid
Psinfo
Pskill
Pslist
Psloglist
Pspasswd
Psservice
Psshutdown
Pssuspend
Pstools