The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Winsock Mutex" vulnerability.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=98075221915234&w=2 | mailing list |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-003 | patch vendor advisory release notes |
https://exchange.xforce.ibmcloud.com/vulnerabilities/6006 | third party advisory vdb entry |