Windows NT NTLMSSP Privilege Elevation Vulnerability Patch (2/7/01)

Patch a flaw in Windows NT 4.0 that could allow an unprivileged process to run code in the NTLMSSP service.
Download

Windows NT NTLMSSP Privilege Elevation Vulnerability Patch (2/7/01) Ranking & Summary

Advertisement

  • Rating:
  • License:
  • Free
  • Publisher Name:
  • Microsoft
  • Publisher web site:
  • http://www.microsoft.com/
  • Operating Systems:
  • Windows NT
  • File Size:
  • 103.12K

Windows NT NTLMSSP Privilege Elevation Vulnerability Patch (2/7/01) Tags


Windows NT NTLMSSP Privilege Elevation Vulnerability Patch (2/7/01) Description

The NTLM Security Support Provider (NTLMSSP) service in Windows NT 4.0 is responsible for handling NTLM authentication requests, and runs by default on all Windows NT 4.0 systems. A flaw in the service's implementation could allow a service request from an unprivileged process to cause code to run in the context of the NTLMSSP service, which runs with Local System privileges. This could enable attackers to programmatically levy requests that would have the effect of running the codes of their choice with System privileges. Workstations and terminal servers are the machines at greatest risk under most conditions.


Windows NT NTLMSSP Privilege Elevation Vulnerability Patch (2/7/01) Related Software