Microsoft Security Bulletin MS02-042

Privilege elevation flaw in Network Connection Manager
Download

Microsoft Security Bulletin MS02-042 Ranking & Summary

Advertisement

  • Rating:
  • License:
  • Update
  • Price:
  • Free to try
  • Publisher Name:
  • By Microsoft
  • Publisher web site:
  • http://www.microsoft.com/
  • Operating Systems:
  • Windows, Windows 2000
  • Additional Requirements:
  • Windows 2000
  • File Size:
  • 235.35K
  • Total Downloads:
  • 47

Microsoft Security Bulletin MS02-042 Tags


Microsoft Security Bulletin MS02-042 Description

The Network Connection Manager (NCM) provides a controlling mechanism for all network connections managed by a host system. Among the functions of the NCM is to call a handler routine whenever a network connection has been established. By design, this handler routine should run in the security context of the user. However, a flaw could make it possible for an unprivileged user to cause the handler routine to run in the security context of LocalSystem, though a very complex process. An attacker who exploited this flaw could specify code of his or her choice as the handler, then establish a network connection in order to cause that code to be invoked by the NCM. The code would then run with full system privileges.


Microsoft Security Bulletin MS02-042 Related Software