Privilege Escalation Vulnerability in Windows 2000/NT Domains

A vulnerability exists in Windows 2000 and Windows NT 4.0 domains that lets an attacker gain administrative access to computers in a trusting domain.

Ken Pfeil

January 31, 2002

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported January 30, 2002, byMicrosoft.

VERSIONS AFFECTED

 

  • Windows 2000

  • Windows NT 4.0

 

DESCRIPTION
A vulnerability exists in Windows 2000 and Windows NT 4.0 domains thatlets an attacker gain administrative access to computers in a trusting domain.This vulnerability stems from the fact that the trusting domaindoesn't verify that the trusted domain is actually authoritative for all theSecurity Identifiers (SIDs) in the authorization data. If one of the SIDs in thelist identifies a user or security group that's not in the trusted domain, thetrusting domain accepts the information and uses it for future access controldecisions. By inserting SIDs into the authorization data at the trusted domain,an attacker can elevate his or her privileges to those associated with any useror group, including the Domain Administrators group for the trusting domain.

 

VENDOR RESPONSE

Thevendor, Microsoft, has released securitybulletin MS02-01to address this vulnerability and recommends that affected users apply thesecurity rollup packages provided in the bulletin.

 

CREDIT
Discovered by AelitaSoftware and Michel Trépanier.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like