vendor:
Windows
by:
Nelson Brito
7.5
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Windows
Affected Version From: All versions of Windows with the Autorun feature enabled
Affected Version To: All versions of Windows with the Autorun feature enabled
Patch Exists: NO
Related CWE:
CPE: o:microsoft:windows
Platforms Tested: Windows
Unknown
Windows Autorun Privilege Escalation
The Windows Autorun feature allows an executable and an icon to be specified for any removable media. However, it can also be abused on fixed and networked drives. Any user with write access to the root of a logical drive can install an executable and specify it in an autorun.inf file. When the drive is accessed later, the code will run with the privileges of the logged-in user, potentially enabling privilege escalation attacks.
Mitigation:
Disable the Autorun feature on Windows systems or restrict write access to the root of logical drives.