PC Tools - Essential tools for your PC
Search
 
 
Features
 
 
Newsletter
 
Security Home > Windows NT, 2000 & XP > Windows NT

RASMAN Security Descriptor Vulnerability

A vulnerability exists that could enable a user to execute arbitrary code on a Windows NT machine under certain conditions, due to an inappropriate ACE in the Remote Access Connection Manager DACL.

Issue

The security descriptor that secures the Remote Access Connection Manager, RASMAN.EXE, contains an inappropriate ACE in its DACL and would allow an unprivileged user to levy requests on it via the Service Control Manager. Among the actions that could be requested is to change the location and name of the executable code for the service. By doing so, a malicious user could substitute arbitrary code for the legitimate service, which then would run in a System Context.

A malicious user could only exploit this vulnerability if he or she had a valid userid and password on the target machine. If the machine allowed users to log on from the network, the vulnerability could be remotely exploited. In addition, the arbitrary code could, under certain conditions, reside on a remote machine. A tool is available to reset the permissions to the appropriate value and eliminate the vulnerability, and should be run against any machine that allows unprivileged users to perform either interactive or network logons under any account.

Affected Products

  • Windows NT Server, Enterprise, Terminal Server and Workstation 4.0

Download

Patch: ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/nt40/Hotfixes-PostSP6/Security/Rasman-fix/

Further Details

Source: Microsoft Corporation

Reference: Microsoft Corporation

Updated: September 30, 1999

>> Recommended Download - secure your PC from spyware, adware and malware now with Spyware Doctor <<

 
  Copyright © 1998-2008 PC Tools. All rights Reserved. Privacy Policy | Legal Notice 


Are you looking for Mac security software?
PC Tools now offers iAntiVirus, a free antivirus product for Mac OS X. Please click below to learn more.

Tell me more No, thanks

Remember my answer