NTLM Security Support Provider (NTLMSSP) service does not properly check the function number in an LPC request, which could allow local users to gain administrator level access.
Link | Tags |
---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-008 | vendor advisory |
http://razor.bindview.com/publish/advisories/adv_NTLMSSP.html | vendor advisory |
http://www.securityfocus.com/bid/2348 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/6076 | vdb entry |