Vulnerability Development mailing list archives

R: office 2k security bug?


From: raist () CTRADE IT (Raistlin)
Date: Wed, 23 Feb 2000 19:14:53 +0100


In short terms: a normal user can gain system access under NT by the
mean's
of the "installation wizard" by reading/writing to the registry

In Windows 2000 there's an explicit distinction between "power users" who
can install applications and "normal users" who cannot. I can figure this is
the answer to your legitimate alert: in fact, it seems that a malicious user
under NT could access some part of the registry in that way.

Raistlin


Current thread: