Microsoft Windows 2000 RunAs Service命名管道劫持漏洞

漏洞信息详情

Microsoft Windows 2000 RunAs Service命名管道劫持漏洞

漏洞简介

Windows 2000版本中的RunAs (runas.exe)存在漏洞。本地用户在服务停止时创建一个欺骗的命名管道,然后在客户端连接到服务时捕获明文用户名和密码。

漏洞公告

The fix for this vulnerability will reportedly be included in Service Pack 3.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com .
@securityfocus.com>

参考网址

来源: BID
名称: 3185
链接:http://www.securityfocus.com/bid/3185

来源: XF
名称: win2k-runas-pipe-authentication(7532)
链接:http://www.iss.net/security_center/static/7532.php

来源: BUGTRAQ
名称: 20011114 RE:Radix Research Reports RADIX1112200101, RADIX1112200102, and RADIX1112200103
链接:http://online.securityfocus.com/archive/1/240136

来源: BUGTRAQ
名称: 20011112 RADIX1112200101
链接:http://online.securityfocus.com/archive/1/236111

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享