vendor:
Windows NT
by:
David Litchfield
7.5
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Windows NT
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
1999
Default ACL Over Winlogon Key Privilege Escalation
The default ACL over the HKEY_Local_MachineSoftwareMicrosoftWindows NTCurrentVersionWinlogon key "System" value includes an entry for Server Operators:Special. A malicious System Operator could place reference to a trojan in this entry. This trojan would be executed under system privileges the next time the system is booted. As the trojan has been called by the system, the system account has privileges to execute code that would elevate the permission of a selected account to "administrator".
Mitigation:
Unknown