Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Microsoft rings alarm on Windows rights bug

Last month's 'design flaw' is this month's security vulnerability

April 18, 2008 12:00 PM ET

Active Comments
Anonymous says: Troll. If your grandma has to deal with web and database servers, she must be familiar with Linux by now....
AB says: The access rights bug has been present in Microsoft(r) IIS and SQL Server since they first appeared in the Windows...


Computerworld - Microsoft Corp. yesterday issued a security alert to warn users of a bug in most versions of Windows, but didn't promise to fix the flaw or -- if it does patch the problem -- say when a fix would be released.

A little more than three weeks ago, Microsoft had denied that the problem was a vulnerability.

In a security advisory published on Thursday, Microsoft categorized the vulnerability as an "elevation of privilege" that, if exploited, could give attackers significantly greater access to the compromised machine. The bug affects Windows XP Professional SP2, and all versions of Windows Server 2003, Windows Vista and the brand-new Windows Server 2008.

Although the flaw is within Windows, attackers could conceivably exploit it through custom Web applications running in Microsoft's Web server, Internet Information Services. It could also be exploited via SQL Server, added Microsoft.

"Web apps usually run in a lesser-privileged mode," said Andrew Storms, director of security operations at nCircle Network Security Inc. "[Using this vulnerability, attackers] could jump that privilege to a LocalSystem account, which is not a long way from an administrative account.

"You can do quite a bit with a LocalSystem account," Storms said.

Several weeks ago, Cesar Cerrudo, a researcher and security consultant in Parana, Argentina, said that he would disclose a Windows flaw at an upcoming conference. The vulnerability, Cerrudo said in late March, could let attackers bypass some of the security schemes in the newest versions of the operating system, including Windows Server 2008.

In a story posted by the SearchSecurity.com Web site, Cerrudo said that attacks could be launched through IIS, and that the threat could be mitigated by running Web applications under a different account from NetworkService, LocalService and LocalSystem.

At the time, Bill Sick, a spokesman for the Microsoft Security Response Center (MSRC), said that Cerrudo's information appeared to be about a "design flaw" rather than a true vulnerability. Sisk also downplayed the threat. "The presentation does not describe methods for an attacker to gain access to these trusted accounts," he told SearchSecurity.com.

Yesterday, however, Cerrudo unveiled the vulnerability in a presentation at HITBSecConf2008, a security conference that opened Monday and wrapped up Thursday in Dubai, United Arab Emirates; Microsoft followed that presentation with its advisory.

Today, the company confirmed that Cerrudo's findings prompted its advisory. "Yes, the security advisory released yesterday and a presentation by a researcher in Dubai relate to the same issue," a company spokeswoman said in an e-mail.

As it often does in its advisories, Microsoft did not promise to create a patch. "Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers," Sisk said in a post to the MSRC blog. "This may include providing a security update through our monthly release."

But Microsoft rarely issues a security advisory without at some later date providing a patch, Storms noted.

The next scheduled release date for a Microsoft patch is May 13.



Jump to comments

Microsoft

Additional Resources

WHITE PAPER
Approximately 60 percent of data migration projects overrun time or budget, while some fail completely. Download this white paper, "Enhancing Your Chance for Successful Data Migration," to learn the critical steps you need to take to execute a data migration project with minimum cost and risk to your business.
WHITE PAPER
Read the Gartner research note to learn why the TCO of a server-based computing deployment used to deliver all applications to users is around 50% lower than that of an unmanaged desktop deployment.
WHITE PAPER
Economic downturns have a tendency to accelerate emerging technologies, boost the adoption of effective solutions, and punish solutions that are not cost competitive or that are out of synch with industry trends. This IDC White Paper presents the results of an IDC survey of 330 companies in Western Europe, Asia/Pacific and the Americas that measures the receptiveness to Linux and takes into consideration changing views driven by the disruptive economic environment that businesses face today.

What People Are Saying

White Papers & Webcasts

Share our Strength
Download Now  

Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...

Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...