SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#960267

Microsoft Windows 2000 fails to apply Group Policy to clients when policy file has been opened using exclusive read access (MS02-016)

Overview

A vulnerability in the locking of Group Policy Files under Windows 2000 may allow a local intruder to circumvent recently applied policy settings.

I. Description

When a user logs onto a Windows 2000 system, a number of "security policy" settings are applied to that user's session. The settings are stored in the Active Directory in an object called the Group Policy Object (GPO). Because the GPO supports file locking like other file system objects, a local attacker may be able to obtain an exclusive-read lock on the GPO. This exclusive-read lock will prevent subsequent logons by all users of the system to use the policy settings in effect before the lock was obtained. This may prevent recently updated policies from being applied to subsequent logons. While this change would affect all users of the system, the transparent nature of the group policy system would not present any clear indication that the policy settings were not correctly applied.

II. Impact

A local intruder who is able to gain an exclusive lock on the policy files may be able to prevent new policy settings from affecting subsequent logons.

III. Solution

Apply a Patch

Microsoft has published patches correcting this vulnerability. The patches are listed in their advisory at:


Systems Affected

VendorStatusDate NotifiedDate Updated
Microsoft CorporationVulnerable16-Jul-2002

References


http://www.microsoft.com/technet/security/bulletin/ms02-016.asp
http://www.securityfocus.com/bid/4438
http://online.securityfocus.com/archive/1/244329
http://www.security.nnov.ru/search/news.asp?binid=1613
http://www.security.nnov.ru/advisories/filelock.asp

Credit

This vulnerability was discovered by security.nnov.

This document was written by Cory F. Cohen.

Other Information

Date Public:2001-12-05
Date First Published:2002-09-27
Date Last Updated:2002-09-27
CERT Advisory: 
CVE-ID(s):CAN-2002-0051
NVD-ID(s):CAN-2002-0051
US-CERT Technical Alerts: 
Metric:4.17
Document Revision:7

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2002 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader