NT Trojan Profile Vulnerability

Solution:
Since the winlogon process creates the new subkey when a new user logs on in the context of the SYSTEM account, only the SYSTEM account needs write access to the ProfileList key and Everyone should only be given read access.



 

Privacy Statement
Copyright 2010, SecurityFocus