PT-2006-4331 · Microsoft · Windows 2000 Sp4+1
Reed Arvin
·
Published
2006-08-08
·
Updated
2019-04-30
·
CVE-2006-3443
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows 2000 SP4
Description
The issue is related to an untrusted search path vulnerability in Winlogon, which can be exploited when SafeDllSearchMode is disabled. This allows local users to gain privileges via a malicious DLL in the UserProfile directory. The vulnerability could enable a logged-on user to take complete control of the system.
Recommendations
For Microsoft Windows 2000 SP4, enable SafeDllSearchMode to prevent the exploitation of this issue.
As a temporary workaround, consider restricting access to the UserProfile directory to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows 2000 Sp4
Windows