Microsoft Windows 2000 RunAs service allows local attacker to bypass pipe authentication
| win2k-runas-pipe-authentication (7532) |
Description:
The RunAs service in Windows 2000 allows a user to run applications or services legitimately as another user. The RunAs service could allow a local attacker to obtain sensitive information such as usernames and passwords. When the RunAs command is executed, a named pipe is created for communication. If the RunAs service is stopped, a local attacker can obtain the user's credentials and create a named pipe using those credentials. The attacker's named pipe would then be executed once another user runs the service.
Consequences:
Gain Access
Remedy:
Apply the latest Windows 2000 Service Pack (SP3 or later), when it becomes available from the Microsoft Web site. See References.
As a workaround, do no use the RunAs service.
References:
- Microsoft Corporation Web site: Service Packs.
- Team RADIX Research Report: RADIX1112200101: RunAs Service Pipe Authentication Failure.
- BID-3185: Microsoft Windows 2000 RunAs Service Named Pipe Hijacking Vulnerability
- CVE-2001-1519: ** DISPUTED ** RunAs (runas.exe) in Windows 2000 allows local users to create a spoofed named pipe when the service is stopped, then capture cleartext usernames and passwords when clients connect to the service. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it.
Platforms Affected:
- Microsoft Windows 2000
Reported:
Nov 12, 2001
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
