main
Report a problem

MS02-064: Windows 2000 Default Permissions Could Allow Trojan Horse Program

configure   on 31 October 2002 - 07:52 · no comments & 472 views

Advertisement (Why?)
Date: 30 October 2002
Software: Windows 2000
Impact: Trojan Horse program execution
Max Risk: Moderate

On Windows 2000, the default permissions provide the Everyone group with Full access (Everyone:F) on the system root folder (typically, C:). In most cases, the system root is not in the search path. However, under certain conditions - for instance, during logon
or when applications are invoked directly from the Windows desktop via Start | Run - it can be.

This situation gives rise to a scenario that could enable an attacker to mount a Trojan horse attack against other users of the same system, by creating a program in the system root with the same name as some commonly used program, then waiting for another user to subsequently log onto the system and invoke the program. The Trojan horse program would execute with the user's own privileges, thereby enabling it to take any action that the user could take.

View: MS Security Bulletin ID MS02-064 for more information

Post a comment · Send to friend Comments · There are no additional comments

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)