Privilege Escalation Vulnerability in Microsoft Utility Manager for Windows

A privilege-elevation vulnerability exists in the way in which Utility Manager launches applications.

Ken Pfeil

July 15, 2004

1 Min Read
ITPro Today logo

Reported July 13, 2004, byMicrosoft

VERSIONS AFFECTED

DESCRIPTION
A privilege-elevation vulnerability exists in the way in which Utility Managerlaunches applications. A logged-on user could force Utility Manager to start anapplication with system privileges, then take complete control of the system. Apotential attacker who successfully exploited this vulnerability could takecomplete control of an affected system, including installing programs; viewing,changing, or deleting data; or creating new accounts that have full privileges.

VENDOR RESPONSE
Microsoft has releasedbulletin MS04-019, "Vulnerability in Utility Manager CouldAllow Code Execution (842526)," to address this vulnerability andrecommends that affected users apply the appropriate patch listed in thebulletin.

CREDIT
Discovered by Cesar Cerrudo of ApplicationSecurity, Inc.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like