SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#107280

Microsoft Windows 2000 Network Dynamic Data Exchange (DDE) executes code as Local System

Overview

The Windows 2000 Network DDE agent permits local users to execute commands with system privileges.

I. Description

Dynamic Data Exchange (DDE) is an interprocess communication mechanism used in Microsoft Windows. A DDE share is an area of memory which is used to store and retrieve data. Network DDE is used between process on two different computers that wish to communicate using DDE. The service that manages this network communication is called the Network DDE Agent. When a share is marked by its creator as a truted share, it can be used by the Network DDE Agent.

When a trusted share is accessed by a local user, part of the request can include an application that will be invoked by the Network DDE Agent. Under Windows 2000, this application will run with Local System privileges. Since any local user can created trusted shares, it is possible for an intruder who already has access to the system to leverage this vulnerability to execute an arbitrary program with Local System privileges. For more information, see Microsoft Security Bulletin MS01-007. Additionally, see the bulletin provided by @Stake on this issue.

II. Impact

Local users can execute arbitrary commands with system privileges.

III. Solution

Apply a patch as described in MS01-007.

Systems Affected

VendorStatusDate Updated
Microsoft CorporationVulnerable13-Jul-2002

References


http://www.microsoft.com/technet/security/bulletin/MS01-007.asp
http://www.microsoft.com/technet/security/bulletin/fq01-007.asp
http://www.atstake.com/research/advisories/2001/a020501-1.txt
http://www.securityfocus.com/bid/2341
http://msdn.microsoft.com/library/default.asp?url=/library/en-us/ipc/netdde_3mcl.asp

Credit

Thanks to Microsoft and @Stake for the information provided in their bulletins.

This document was written by Shawn V Hernan based on information provided by Microsoft and @Stake.

Other Information

Date Public02/05/2001
Date First Published07/13/2002 07:58:54 PM
Date Last Updated07/13/2002
CERT Advisory 
CVE NameCAN-2001-0015
US-CERT Technical Alerts 
Metric25.73
Document Revision11

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2002 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader