BugTraq
Privilege escalation flaw in MDaemon 7.2. Nov 29 2004 03:46PM
Reed Arvin (reedarvin gmail com) (1 replies)


Summary:

A privilege escalation flaw exists in MDaemon 7.2 (http://www.mdaemon.com).

Details:

A privilege escalation technique can be used to gain SYSTEM level access while interacting with the MDaemon tray icon.

Vulnerable Versions:

MDaemon 7.2

Solutions:

The vendor was notified of the issue. There was no response.

Exploit:

1. Double click on the mail icon in the Taskbar to open the Alt-N MDaemon Pro window.

2. Click File, click New

3. Notepad should open. In Notepad click File, click Open

4. In the Files of type: field choose All Files

5. Navagate to %WINDIR%\System326. Right click cmd.exe and choose Open

7. A new command shell will open with SYSTEM privileges

Discovered by Reed Arvin reedarvin[at]gmail[dot]com

[ reply ]
Re: Privilege escalation flaw in MDaemon 7.2. Nov 30 2004 07:21AM
kf_lists (kf_lists secnetops com)


 

Privacy Statement
Copyright 2010, SecurityFocus