SMS: French Security Issue: Wuser32.exe Has Everyone Full Control Permissions (257364)
The information in this article applies to:
- Microsoft Systems Management Server 2.0
This article was previously published under Q257364 SYMPTOMS
If the Systems Management Server (SMS) 2.0 Remote Control feature is installed and enabled on a computer, the folder in which the Remote Control agent is located has its permissions set to Everyone Full Control by default. If a malicious user were to replace the client code with other code, the code would run automatically in a System context the next time that user rebooted the computer and logged on. This vulnerability exists only if the Remote Control feature is enabled; no other SMS features are affected by it.
CAUSE
The client code for the Remote Control agent runs in the highly privileged System security context. However, it is installed in a folder that by default allows any user who can interactively log on to the computer to have complete access to the folder.
RESOLUTIONA supported fix is now available from Microsoft, but it is only intended to correct the problem that is described in this article. Apply it only to computers that are experiencing this specific problem. This fix may receive additional testing. Therefore, if you are not severely affected by this problem, Microsoft recommends that you wait for the next Systems Management Server service pack that contains this hotfix. To resolve this problem immediately, contact Microsoft Product Support Services to obtain the fix. For a complete list of Microsoft Product Support Services phone numbers and information about support costs, visit the following Microsoft Web site: NOTE: In special cases, charges that are ordinarily incurred for support calls may be canceled if a Microsoft Support Professional determines that a specific update will resolve your problem. The typical support costs will apply to additional support questions and issues that do not qualify for the specific update in question.
The French version of this fix should have the following file attributes or later:
Date Time Version Size File name Platform
----------------------------------------------------------------
01/04/2000 03:16a 67 Compver.ini
03/28/2000 04:32p 2.0.1380.1108 1.61 MB Remctrl.exe Intel
03/28/2000 04:44p 2.0.1380.1108 1.23 MB Remctrl.exe Alpha
NOTE: Due to file dependencies, the most recent hotfix or feature that contains the above files may also contain additional files. STATUS
Microsoft has confirmed this to be a problem in Systems Management Server version 2.0.
Modification Type: | Minor | Last Reviewed: | 10/6/2005 |
---|
Keywords: | kbBug kbfix kbHelpDesk kbQFE kbSecurity KbSECVulnerability KB257364 |
---|
|