CVE-2004-2730

Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSuspend before 1.05, and (10) PsShutdown before 2.32, does not properly disconnect from remote IPC$ and ADMIN$ shares, which allows local users to access the shares with elevated privileges by using the existing share mapping.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:microsoft:psexec:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:psgetsid:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:psinfo:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:pskill:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:pslist:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:psloglist:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:pspasswd:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:psservice:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:psshutdown:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:pssuspend:*:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:sysinternals_pstools:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:54

Type Values Removed Values Added
References () http://secunia.com/advisories/12108 - Vendor Advisory () http://secunia.com/advisories/12108 - Vendor Advisory
References () http://securitytracker.com/id?1010737 - () http://securitytracker.com/id?1010737 -
References () http://www.osvdb.org/8140 - () http://www.osvdb.org/8140 -
References () http://www.securityfocus.com/bid/10759 - Patch () http://www.securityfocus.com/bid/10759 - Patch
References () http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=28304 - () http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=28304 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/16743 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/16743 -

Information

Published : 2004-12-31 05:00

Updated : 2024-11-20 23:54


NVD link : CVE-2004-2730

Mitre link : CVE-2004-2730

CVE.ORG link : CVE-2004-2730


JSON object : View

Products Affected

microsoft

  • psshutdown
  • psexec
  • sysinternals_pstools
  • pslist
  • psgetsid
  • psinfo
  • pspasswd
  • pskill
  • psservice
  • psloglist
  • pssuspend
CWE
CWE-264

Permissions, Privileges, and Access Controls