Privilege Escalation Vulnerability in Windows 2000/NT Domains
A vulnerability exists in Windows 2000 and Windows NT 4.0 domains that lets an attacker gain administrative access to computers in a trusting domain.
January 31, 2002
Reported January 30, 2002, byMicrosoft.
VERSIONS AFFECTED
Windows 2000
Windows NT 4.0
DESCRIPTION
A vulnerability exists in Windows 2000 and Windows NT 4.0 domains thatlets an attacker gain administrative access to computers in a trusting domain.This vulnerability stems from the fact that the trusting domaindoesn't verify that the trusted domain is actually authoritative for all theSecurity Identifiers (SIDs) in the authorization data. If one of the SIDs in thelist identifies a user or security group that's not in the trusted domain, thetrusting domain accepts the information and uses it for future access controldecisions. By inserting SIDs into the authorization data at the trusted domain,an attacker can elevate his or her privileges to those associated with any useror group, including the Domain Administrators group for the trusting domain.
VENDOR RESPONSE
Thevendor, Microsoft, has released securitybulletin MS02-01to address this vulnerability and recommends that affected users apply thesecurity rollup packages provided in the bulletin.
CREDIT
Discovered by AelitaSoftware and Michel Trépanier.
About the Author
You May Also Like