Named Pipe Impersonation

An attacker can created named pipes for services in a manner that would allow elevated privileges to be acheived

ITPro Today Staff

August 2, 2000

1 Min Read
ITPro Today logo

 

Reported August 2, 2000 by Guardent

VERSIONS EFFECTED

Windows 2000 Professional, Server, Advanced Server DESCRIPTION

The Windows 2000 Service Control Manager (SCM) creates a named pipe for each service as it starts. It is possible for an attacker to create the named pipe for a service before the SCM can do so, at which point elevated privileges could be achieved based on any valid user account including LocalSystem.

VENDOR RESPONSE

Microsoft released a FAQ, a patch, and a Support Online article Q269523 regarding this matter.  

CREDIT
Discovered by Guardent

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like