|
|
Info |
Last Modified |
| 10 months ago |
|
|
|
|
Description |
Microsoft Windows 2000 has been reported to contain a flaw that may lead to information disclosure by using the RUN AS service. Memory used by the runas.exe program is not cleared after use, and might be assigned to another program. An attacker with local privileges can reportedly gain access to this memory, potentially gaining sensitive information. However, the vendor notes that to gain access to this program and memory, one would need administrator privileges making this a non-issue.
|
|
Classification |
Location:
Local Access Required
Attack Type:
Cryptographic,
Information Disclosure
Impact:
Loss of Confidentiality
Exploit:
Exploit Unknown
OSVDB:
Myth/Fake
|
|
Solution |
The vulnerability reported is incorrect. No solution required.
|
|
Products |
|
Windows
 |
2000 SP2 |
2000 SP1 |
2000 |
|
|
|
|
Credit |
- Steve - steve
securesolutions.org - Camisade LLC
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|