Backdoor in R.I. Soft Systems Living Waterfalls Screensaver

A back door exists in the Living Waterfalls screensaver from Rhode Island (RI) Soft Systems.

Ken Pfeil

July 4, 2001

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported June 27, 2001, by SteveJohns.

VERSIONS AFFECTED

 

  • Rhode Island Soft Systems’ Living Waterfalls demo screensaver for Windows 2000, Windows NT, and Windows 9x

 

DESCRIPTION
A back door exists in theLiving Waterfalls demo screensaver from Rhode Island (RI) Soft Systems. By pressingthe space bar on the keyboard, it's possible to circumvent the screensaver'slock workstation function. A malicious user can make the default Web browserappear with the RI Soft System Web site by using the security context of thecurrently logged-on user. From there, the attacker can run explorer.exe in thebrowser’s address window to get the desktop and to run any other program underthis context. A malicious user can also exploit this vulnerability remotelythrough Windows 2000 Terminal Services Advanced Client (formerly known asTerminal Services Web Client). 

 

VENDOR RESPONSE

Thevendor, Rhode Island SoftSystems, was notified and doesn't intend to release a fix for this issue. Towork around this vulnerability, a user can uninstall the screensaver software.

 

CREDIT
Discoveredby Steve Johns.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like