Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/8092 | vdb entry third party advisory |
http://www.securityfocus.com/bid/4053 | vdb entry third party advisory patch |
http://www.osvdb.org/2042 | vdb entry broken link |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1022 | vdb entry third party advisory signature |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-003 | patch vendor advisory |