ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Microsoft debugger flaw yields system keys

Published: 23 May 2002 09:34 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft warned Windows NT and 2000 users on Wednesday of a new flaw in its debugger tools that could let attackers give themselves complete control of a system once they've gained basic access to that system.

The vulnerability involves a flaw in the debugger's authorisation feature. The flaw lets any user run any program on the system, with the highest privileges.

The hole could be used in conjunction with other Windows vulnerabilities that allow a remote attacker to run as a local user, said Marc Maiffret, chief hacking officer with network-protection company eEye Digital Security.

"By itself, I would say it's not that dangerous, but coupled with other vulnerabilities, it's nasty," Maiffret said. "It makes threats like Nimda possible."

The Nimda worm used a similar double whammy to gain base-level access to a system and then elevate its privileges to take control of the infected computer.

Microsoft gave the vulnerability a "critical" rating for client systems but would not estimate what portion of Windows NT 4.0 and Windows 2000 computers might be vulnerable to the new flaw.

"Being able to log on to the computer in the first place, and being able to run code (once logged on), are the two limiting factors for this flaw," said Christopher Budd, security program manager for Microsoft's security response center.

For example, a guest account could be co-opted by an attacker and used to exploit the flaw to run code only if the system's administrator allowed guests access to the console and let them introduce code to the machine, Budd said.

Microsoft has posted an advisory and a patch for the problem.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
42 out of 79 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

IMMEDIATE DESKTOP SUPPORT OPPORTUNITY WEST LONDON 25-30K

MS Administration, data Recovery and Antivirus Procedures, Telephony Systems, MS 2003 & NT, MS Active Directory 2000/2003 and MS Exchange messaging ...

NT SYSTEMS ENGINEER - CITRIX PS4 - FINANCE - 50K

An NT Systems Engineer with extensive experience of administering Windows 2003 server, Active Directory, Exchange2003, Citrix PS4, MSClustering and ...

IT Support Engineer (Terminal Services 2003,Wins Server,AD,VMWare)

Successful candidates will be working in a Windows Server team, administering, installing and troubleshooting for Windows NT, 2000/2003 server ...

Discussions

harpless harpless

SAP goes big business

Friday 25 July 2008, 6:17 PM

1 comment
pjc158 pjc158

Will Drizzle rain on Sun's MySql

Friday 25 July 2008, 5:30 PM

1 comment
pjc158 pjc158

Show me the money!

Friday 25 July 2008, 5:18 PM

5 comments

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal