Vulnerability CVE-1999-1431


Published: 2005-01-07   Modified: 2012-02-12

Description:
ZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 applications (such as Word), installing software into the TEMP directory, and changing the name to that for an allowed application, such as Winword.exe.

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.6/10
6.4/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Microsoft -> Zero administration kit 

 References:
http://marc.info/?l=ntbugtraq&m=91576100022688&w=2
http://marc.info/?l=ntbugtraq&m=91606260910008&w=2
http://www.securityfocus.com/bid/181

Copyright 2020, cxsecurity.com

 

Back to Top