-
February 10th, 2002, 02:53 AM
#1
Vulnerability:Microsoft Exchange Inappropriate Registry Permissions
Microsoft Exchange Inappropriate Registry Permissions Vulnerability
A flaw has been reported in the Microsoft Exchange System Attendant, which could allow unprivileged users access to the WinReg key.
The WinReg key controls users and groups ability to connect remotely to the registry.
The System Attendant must ensure the that the Microsoft Exchange System Manager can remotely connect, in doing so, the System Attendant adds the 'Everyone' group to the WinReg key.
Exploit: No exploit code required.
Remote: Yes
Solution: Microsoft has released a patch which addresses this issue:
http://download.microsoft.com/downlo...tserver/Patch/ 06.00.21.5770/NT5/EN-US/Q316056engi386.EXE
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|