Help and Support

Article ID: 303628 - Last Review: March 2, 2007 - Revision: 2.2

Relative Path Issue Can Allow Program to Be Run Under the System Context

This article was previously published under Q303628

On This Page

Expand all | Collapse all

SYMPTOMS

A domain user could potentially run a process under the System context if the program file is renamed as a screen saver file in the root folder of the system drive. System must have Read rights to the folder under which the process is renamed.

RESOLUTION

Windows NT 4.0

To resolve this problem, obtain the Windows NT 4.0 Security Rollup Package. For additional information, click the article number below to view the article in the Microsoft Knowledge Base:
299444  (http://support.microsoft.com/kb/299444/EN-US/ ) Post-Windows NT 4.0 Service Pack 6a Security Rollup Package (SRP)

Microsoft Windows NT Server version 4.0, Terminal Server Edition

To resolve this problem, obtain the Windows NT Server 4.0, Terminal Server Edition, Security Rollup Package (SRP). For additional information about the SRP, click the article number below to view the article in the Microsoft Knowledge Base:
317636  (http://support.microsoft.com/kb/317636/EN-US/ ) Windows NT Server 4.0, TerminalServer Edition, Security Rollup Package

STATUS

Microsoft has confirmed that this problem may cause a degree of security vulnerability in Microsoft Windows NT 4.0 and Windows NT Server version 4.0, Terminal Server Edition.

APPLIES TO
  • Microsoft Windows NT Server 4.0, Terminal Server Edition Service Pack 4
  • Microsoft Windows NT Server 4.0, Terminal Server Edition Service Pack 5
  • Microsoft Windows NT Server 4.0, Terminal Server Edition Service Pack 6
  • Microsoft Windows NT Server 4.0 Standard Edition
  • Microsoft Windows NT 4.0 Service Pack 1
  • Microsoft Windows NT 4.0 Service Pack 2
  • Microsoft Windows NT 4.0 Service Pack 3
  • Microsoft Windows NT 4.0 Service Pack 4
  • Microsoft Windows NT 4.0 Service Pack 5
  • Microsoft Windows NT 4.0 Service Pack 6a
  • Microsoft Windows NT Server 4.0 Enterprise Edition
  • Microsoft Windows NT Workstation 4.0 Developer Edition
  • Microsoft Windows NT Workstation 4.0
Keywords: 
kbbug kbfix kbsecurity KB303628

Article Translations