Privilege Escalation Vulnerability in Microsoft Utility Manager for Windows
A privilege-elevation vulnerability exists in the way in which Utility Manager launches applications.
July 15, 2004
Reported July 13, 2004, byMicrosoft
VERSIONS AFFECTED
DESCRIPTION
A privilege-elevation vulnerability exists in the way in which Utility Managerlaunches applications. A logged-on user could force Utility Manager to start anapplication with system privileges, then take complete control of the system. Apotential attacker who successfully exploited this vulnerability could takecomplete control of an affected system, including installing programs; viewing,changing, or deleting data; or creating new accounts that have full privileges.
VENDOR RESPONSE
Microsoft has releasedbulletin MS04-019, "Vulnerability in Utility Manager CouldAllow Code Execution (842526)," to address this vulnerability andrecommends that affected users apply the appropriate patch listed in thebulletin.
CREDIT
Discovered by Cesar Cerrudo of ApplicationSecurity, Inc.
Read more about:
MicrosoftAbout the Author
You May Also Like