Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
The Weakness of Windows Impersonation Model May 16 2006 06:25PM
Brian L. Walche (gsw gentlesecurity com)
The Weakness of Windows Impersonation Model
<http://www.gentlesecurity.com/04302006.html>

Summary

1. Network Service account?s context is elevated to LocalSystem.
2. A context of MS SQL service running as unique user account is
elevated up to LocalSystem.
3. Any service?s context could be elevated...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus