MSMVPS.COM

The Ultimate Destination for Blogs by Current and Former Microsoft Most Valuable Professionals.
Welcome to MSMVPS.COM Sign in | Help
in Search

Harry Waldron - Microsoft MVP Blog

Security News and Best Practices for corporate and home users

Windows XP/Vista/2003 - Local security disclosure vulnerability

This new security vulnerability is rated low-risk and it can only be manipulated by local users (rather than via remote attacks).

Windows XP/Vista/2003 - Local security disclosure vulnerability
http://www.frsirt.com/english/advisories/2007/0701
http://secunia.com/advisories/24245/

QUOTE: A weakness has been identified in Microsoft Windows, which could be exploited by malicious users to disclose sensitive information. This issue is due to an error within the directory-change API that does not properly validate user's permission for child objects when retrieving information regarding objects that they do not have "LIST" permissions for.  This could be exploited by local attackers to gather information about protected files (e.g. their names), facilitating further attacks.

CVE ID : CVE-2007-0843
Rated as : Low Risk
Remotely Exploitable : No
Locally Exploitable : Yes

Only published comments... Feb 23 2007, 07:07 PM by harry

Leave a Comment

(required) 
(optional)
(required) 
Submit
Powered by Community Server (Commercial Edition), by Telligent Systems