Microsoft Windows 2000RunAs用户证书曝光漏洞

漏洞信息详情

Microsoft Windows 2000RunAs用户证书曝光漏洞

漏洞简介

** 争议 **Windows 2000的RunAs (runas.exe)在内存中储存明文认证信息。攻击者可以通过执行在终止RunAs命令后分配相同内存页面的进程获得用户名和密码。

漏洞公告

The fix for this vulnerability will reportedly be included in Service Pack 3.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com .
@securityfocus.com>

参考网址

来源: XF
名称: win2k-runas-reveal-information(7531)
链接:http://www.iss.net/security_center/static/7531.php

来源: VULNWATCH
名称: 20011112 RADIX1112200102
链接:http://archives.neohapsis.com/archives/vulnwatch/2001-q4/0041.html

来源: BID
名称: 3184
链接:http://www.securityfocus.com/bid/3184

来源: BUGTRAQ
名称: 20011114 RE:Radix Research Reports RADIX1112200101, RADIX1112200102, and RADIX1112200103
链接:http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00100.html

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享