Backdoor in R.I. Soft Systems Living Waterfalls Screensaver
A back door exists in the Living Waterfalls screensaver from Rhode Island (RI) Soft Systems.
July 4, 2001
Reported June 27, 2001, by SteveJohns.
VERSIONS AFFECTED
Rhode Island Soft Systems’ Living Waterfalls demo screensaver for Windows 2000, Windows NT, and Windows 9x
DESCRIPTION
A back door exists in theLiving Waterfalls demo screensaver from Rhode Island (RI) Soft Systems. By pressingthe space bar on the keyboard, it's possible to circumvent the screensaver'slock workstation function. A malicious user can make the default Web browserappear with the RI Soft System Web site by using the security context of thecurrently logged-on user. From there, the attacker can run explorer.exe in thebrowser’s address window to get the desktop and to run any other program underthis context. A malicious user can also exploit this vulnerability remotelythrough Windows 2000 Terminal Services Advanced Client (formerly known asTerminal Services Web Client).
VENDOR RESPONSE
Thevendor, Rhode Island SoftSystems, was notified and doesn't intend to release a fix for this issue. Towork around this vulnerability, a user can uninstall the screensaver software.
CREDIT
Discoveredby Steve Johns.
About the Author
You May Also Like