Help and Support
 

powered byLive Search

Internet Explorer 5 Task Scheduler Allows Privilege Elevation on Windows NT

Retired KB ArticleThis article was written about products for which Microsoft no longer offers support. Therefore, this article is offered "as is" and will no longer be updated.
Article ID:246972
Last Review:September 27, 2007
Revision:1.2
This article was previously published under Q246972

SYMPTOMS

When you use the schedule feature for updating Web pages that is included with Internet Explorer version 5 to schedule jobs to run at a designated time, it may be possible for a malicious user to obtain elevated privileges on your computer and run a program on the local computer in the System context.

NOTE: Windows NT 4.0 includes a native task scheduler, known as the Schedule or AT service, that does not have this vulnerability. Only computers that are running Windows NT 4.0 with Internet Explorer version 5 installed may be affected by this vulnerability.

Back to the top

CAUSE

The Internet Explorer version 5 scheduling feature enforces control at two points: it restricts who can use the AT utility to create AT jobs, and it only runs AT jobs that are owned by a member of the local Administrators group. However, if a malicious user has Change access to a file owned by an administrator, he or she could modify it to be a valid AT job and place it in the appropriate folder. This would bypass the control mechanism and allow the job to be run. Internet Explorer version 5.01 eliminates this vulnerability by digitally signing all AT jobs at creation time and verifying the signature at run time.

Back to the top

RESOLUTION

To resolve this issue, upgrade the computer running Internet Explorer version 5 to Internet Explorer version 5.01. You can obtain Internet Explorer 5.01 from the following Microsoft Web site:
http://www.microsoft.com/windows/IE/ (http://www.microsoft.com/windows/IE/)

Back to the top

STATUS

Microsoft has confirmed that this is a problem in Windows NT 4.0.

Back to the top

MORE INFORMATION

For related information about this problem, please visit the following Microsoft Web site:
http://www.microsoft.com/technet/security/bulletin/MS99-051.mspx (http://www.microsoft.com/technet/security/bulletin/MS99-051.mspx)
For additional security-related information about Microsoft products, please visit the following Microsoft Web site:
http://www.microsoft.com/security/ (http://www.microsoft.com/security/)

Back to the top


APPLIES TO
Microsoft Internet Explorer 5.0

Back to the top

Keywords: 
kbprb KB246972

Back to the top

Article Translations

 

Other Support Options

  • Need More Help?
    Contact a Support professional by E-mail, Online or Phone.
  • Customer Service
    For non-technical assistance with product purchases, subscriptions, online services, events, training courses, corporate sales, piracy issues, and more.
  • Newsgroups
    Pose a question to other users. Discussion groups and Forums about specific Microsoft products, technologies, and services.