Microsoft Exchange 2000 System Attendant Incorrect v.1.0

Advertisement
Advertisement

The Microsoft Exchange System Attendant is one of the core services in Microsoft Exchange. It performs a variety of functions related to the on-going maintenance of the Exchange system. To allow remote administration of an Exchange Server using the Exchange System Manager Microsoft Management Console (MMC) snap in, the System Attendant makes changes to the permissions on the Windows Registry to allow Exchange Administrators to remotely update configuration settings stored in the Registry.There is a flaw in how the System Attendant makes these Registry configuration changes. This flaw could allow an unprivileged user to remotely access configuration information on the server. Specifically, this flaw inappropriately gives the "Everyone" group privileges to the WinReg key. This key controls the ability of users and groups to remotely connect to the Registry. By default, only Administrators are given the ability to remotely connect to the Registry, by granting permissions on this key.The flaw does not grant any abilities beyond the ability to connect remotely. However, an attacker's ability to make changes to the Registry once they have successfully connected would be dictated by the permissions on the specific keys within the Registry itself. Thus, while this vulnerability does not itself give an attacker the ability to change Registry settings, it could be used in conjunction with inappropriately permissive registry settings to gain access to, and make changes to a systems Registry.

The Microsoft Exchange System Attendant is one ...

 
  • Microsoft Exchange 2000 System Attendant Incorrect
  • 1.0
  • 5am Code
  • Windows 2000
  • Shareware
  • 5.6 Mb
  • 139
 
 

Review Microsoft Exchange 2000 System Attendant Incorrect

  • captcha
 

Other software of 5am Code
  • 2007 Microsoft Office Suite Service Pack 1  v.1.0The 2007 Microsoft Office suite Service Pack 1 delivers important customer-requested stability and performance improvements, while incorporating further enhancements to user security. This service pack also includes all of the updates released for ...
  • 2007 Office System Converter: Microsoft Filter Pack  v.1.0Will install and register IFilters with the Microsoft Windows Indexing Service.The package will install and register IFilters with the Microsoft Windows Indexing Service. These IFilters are used by Microsoft Search products to index the contents of ...

New System Tools software
  • VanDyke ClientPack for Windows, Mac and UNIX  v.8.3.2VanDyke ClientPack is a suite of tools for securely automating file transfer, shell, and public-key administration tasks. Secure automation increases compliance with security policies, saves time, and reduces potential human error.
  • WinToHDD  v.2.8 Release 1WinToHDD allows you to install or reinstall Windows 10/8/7/vista/2016/2012/2008 without using a CD/DVD or USB drive, and you can use it to create a Windows installation USB to install any version of Windows 10/8/7/Vista/2016/2012/2008 (64 & 32 bits).
  • AgaueEye  v.0.39a free hardware monitor for Windows, you can see your CPU/GPU/MB/HDD/RAM state in desktop or overclock your GPU, AgaueEye also support in-game overlay for popular games, so you can monitor the hardware state in games(over 3000 games supported now), t ...