Named Pipe Impersonation
An attacker can created named pipes for services in a manner that would allow elevated privileges to be acheived
ITPro Today Staff
August 2, 2000
1 Min Read
Reported August 2, 2000 by Guardent
VERSIONS EFFECTED
Windows 2000 Professional, Server, Advanced Server DESCRIPTION
The Windows 2000 Service Control Manager (SCM) creates a named pipe for each service as it starts. It is possible for an attacker to create the named pipe for a service before the SCM can do so, at which point elevated privileges could be achieved based on any valid user account including LocalSystem.
VENDOR RESPONSE
Microsoft released a FAQ, a patch, and a Support Online article Q269523 regarding this matter.
CREDIT
Discovered by Guardent
About the Author
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.
You May Also Like