Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> Windows >> SMB Registry : permissions of keys that can lead to admin


Vulnerability Assessment Details

SMB Registry : permissions of keys that can lead to admin

Vulnerability Assessment Summary
Acertains the access rights of a remote key

Detailed Explanation for this Vulnerability Assessment

Summary :

Local users can gain administrator rights.

Description :

The following keys contain the name of the program that shall be started
when the computer starts. The users who have the right to modify them can
easily make the admin run a trojan program which will give them admin
rights.

Solution :

Use regedt32 and set the permissions of this key to :

- Admin group : Full Control
- System : Full Control
- Everyone : Read

Make sure that 'Power Users' do not have any special privilege for this key.

Network Security Threat Level:

High / CVSS Base Score : 7
(AV:L/AC:L/Au:NR/C:C/A:C/I:C/B:N)

Networks Security ID:

Vulnerability Assessment Copyright: This script is Copyright (C) 2005 Tenable Network Security

Cables, Connectors


Vintage Dell Latitude C640 Retro Laptop Windows 98 SE Office 2000 Serial port picture

Vintage Dell Latitude C640 Retro Laptop Windows 98 SE Office 2000 Serial port

$199.99



Vintage OEM Gateway (SK-9922) PS/2 Wired Black  Keyboard, Tested picture

Vintage OEM Gateway (SK-9922) PS/2 Wired Black Keyboard, Tested

$12.00



VINTAGE DIGITAL COMPUTER KEYBOARD PS/2 RT101 FULLY RESTORED picture

VINTAGE DIGITAL COMPUTER KEYBOARD PS/2 RT101 FULLY RESTORED

$98.34



VINTAGE PC IBM SOFTWARE S3G GRAPHICS OPTION BY ATTATCHMATE 1987 PROGRAM GRAPHICS picture

VINTAGE PC IBM SOFTWARE S3G GRAPHICS OPTION BY ATTATCHMATE 1987 PROGRAM GRAPHICS

$29.99



RARE Vintage Finisar's Medusa Labs Protocol Training Roadshow Mens Shirt Size M picture

RARE Vintage Finisar's Medusa Labs Protocol Training Roadshow Mens Shirt Size M

$25.08



Vintage Apple Newton Stylus picture

Vintage Apple Newton Stylus

$11.81



NIB Vintage epower 3d Scrolling USB ps/2 Optical Mouse With Diskette 400dpi NEW picture

NIB Vintage epower 3d Scrolling USB ps/2 Optical Mouse With Diskette 400dpi NEW

$14.99



NEW Manufacture OLD STYLE Oval 3 Prong Power Cord HP style 125V 7A 875W Vintage picture

NEW Manufacture OLD STYLE Oval 3 Prong Power Cord HP style 125V 7A 875W Vintage

$39.95



Vintage scorpius 980n plus Mechanical USB keyboard picture

Vintage scorpius 980n plus Mechanical USB keyboard

$29.00



Vintage Gateway 2000 P55C-200 Desktop PC Pentium MMX 96MB Ram Win 98 Tested  picture

Vintage Gateway 2000 P55C-200 Desktop PC Pentium MMX 96MB Ram Win 98 Tested

$169.99



Discussions

No Discussions have been posted on this vulnerability.