vendor:
Windows Server 2003
by:
Cesar
7.2
CVSS
HIGH
Token Kidnapping
264
CWE
Product Name: Windows Server 2003
Affected Version From: Windows 2003
Affected Version To: Windows 2003
Patch Exists: No
Related CWE: N/A
CPE: o:microsoft:windows_server_2003
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2008
Windows 2003 PoC Exploit for Token Kidnapping
This exploit allows an attacker to execute code under the SYSTEM account on Windows 2003. This is possible because Windows services accounts can impersonate other processes, such as IIS 6 worker processes. If an attacker can run code from an ASP .NET or classic ASP web application, they can own Windows. Additionally, if an attacker has access to a SQL Server, they can execute the exploit using xp_cmdshell. The PoC exploit can be found at http://www.argeniss.com/research/Churrasco.zip
Mitigation:
Restrict user access to ASP .NET and classic ASP web applications, and limit access to SQL Server.