PT-2006-4331 · Microsoft · Windows 2000 Sp4+1

Reed Arvin

·

Published

2006-08-08

·

Updated

2019-04-30

·

CVE-2006-3443

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows 2000 SP4
Description The issue is related to an untrusted search path vulnerability in Winlogon, which can be exploited when SafeDllSearchMode is disabled. This allows local users to gain privileges via a malicious DLL in the UserProfile directory. The vulnerability could enable a logged-on user to take complete control of the system.
Recommendations For Microsoft Windows 2000 SP4, enable SafeDllSearchMode to prevent the exploitation of this issue. As a temporary workaround, consider restricting access to the UserProfile directory to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-3443

Affected Products

Windows 2000 Sp4
Windows