Flaw in Windows WM_TIMER Message Handling

By TS | Thomas
Dec 12, 2002
  1. Issue:
    By default, several of the processes running in the interactive desktop do so with LocalSystem privileges. As a result, an attacker who had the ability to log onto a system interactively could potentially run a program that would levy a WM_TIMER request upon such a process, causing it to take any action the attacker specified. This would give the attacker complete control over the system. In addition to addressing this vulnerability, the patch also makes changes to several processes that run on the interactive desktop with high privileges.

    Affected Software:
    Microsoft Windows NT 4.0
    Microsoft Windows NT 4.0, Terminal Server Edition
    Microsoft Windows 2000
    Microsoft Windows XP

    Patch availability:
    Windows NT 4.0:
    All except Japanese NEC & Chinese - Hong Kong
    Japanese NEC
    Chinese - Hong Kong

    Windows NT 4.0, Terminal Server Edition:

    Windows 2000:
    All except Japanese NEC
    Japanese NEC
    Windows XP:
    32-bit Edition
    64-bit Edition
Topic Status:
Not open for further replies.

Similar Topics

Add your comment to this article

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...