Microsoft Exchange 2000 System Attendant Incorrect v.1.0

Advertisement
Advertisement

The Microsoft Exchange System Attendant is one of the core services in Microsoft Exchange. It performs a variety of functions related to the on-going maintenance of the Exchange system. To allow remote administration of an Exchange Server using the Exchange System Manager Microsoft Management Console (MMC) snap in, the System Attendant makes changes to the permissions on the Windows Registry to allow Exchange Administrators to remotely update configuration settings stored in the Registry.There is a flaw in how the System Attendant makes these Registry configuration changes. This flaw could allow an unprivileged user to remotely access configuration information on the server. Specifically, this flaw inappropriately gives the "Everyone" group privileges to the WinReg key. This key controls the ability of users and groups to remotely connect to the Registry. By default, only Administrators are given the ability to remotely connect to the Registry, by granting permissions on this key.The flaw does not grant any abilities beyond the ability to connect remotely. However, an attacker's ability to make changes to the Registry once they have successfully connected would be dictated by the permissions on the specific keys within the Registry itself. Thus, while this vulnerability does not itself give an attacker the ability to change Registry settings, it could be used in conjunction with inappropriately permissive registry settings to gain access to, and make changes to a systems Registry.

The Microsoft Exchange System Attendant is one ...

 
  • Microsoft Exchange 2000 System Attendant Incorrect
  • 1.0
  • 5am Code
  • Windows 2000
  • Shareware
  • 5.6 Mb
  • 145
 
 

Review Microsoft Exchange 2000 System Attendant Incorrect

  • captcha
 

Other software of 5am Code
  • 2007 Microsoft Office Suite Service Pack 1  v.1.0The 2007 Microsoft Office suite Service Pack 1 delivers important customer-requested stability and performance improvements, while incorporating further enhancements to user security. This service pack also includes all of the updates released for ...
  • 2007 Office System Converter: Microsoft Filter Pack  v.1.0Will install and register IFilters with the Microsoft Windows Indexing Service.The package will install and register IFilters with the Microsoft Windows Indexing Service. These IFilters are used by Microsoft Search products to index the contents of ...

New System Tools software
  • Eusing Cleaner  v.5.0Eusing Cleaner allows you to find and remove the unused files in your system, invalid registry entries, delete your internet history, defrag windows registry, provides plug-in support to clean the history for third-party applications.
  • WinToUSB  v.4.1WinToUSB allows you to install/clone Windows 10/8.1/8/7 to an external hard drive or USB flash drive as a bootable Windows USB, it also supports creating a Windows installation USB drive, so you can install Windows from the USB flash drive easily.
  • Driver Booster  v.5.5.1.844Driver Booster 5, with its new interactive interface and greatly expanded database which can support more than 1,000,000 drivers and game components, is an easy-to-use yet powerful driver updater.
  • Tweaking.Com Windows Repair  v.4.0.22Tweaking.com - Windows Repair is a tool designed help fix a large majority of known Windows problems including; registry errors, file permissions, issues with Internet Explorer, Windows Updates, Windows Firewall and more.
  • Microsoft Exchange 2000 Server Standalone SMTP Sec UpdateThis update addresses the "Windows 2000 SMTP Mail Relaying" security vulnerability in the Windows 2000 Simple Mail Transfer Protocol (SMTP) service and is discussed in Microsoft Security Bulletin MS01-037. Download now to prevent malicious users from ...
  • Microsoft Exchange Server 2007  v.08.01.0240.006Microsoft Exchange Server 2007 provides built-in protection technologies to help keep the e-mail system up and running and better protected from outside threats while allowing employees to work from wherever they are using a variety of clients ...