Windows XP Task Scheduler Local Privilege Escalation (Advisory)



=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
= Advisory: Windows XP Task Scheduler Local Privilege Escalation
=
= Author: Daniel Hückmann (zipk0der) zipk0der@xxxxxxxxxxxxxxxxxxxx
=
= Released at: http://www.pandora-security.com
=
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

1. Overview.

In Windows XP, the task scheduler service runs as "SYSTEM" (local service);
this is akin to running cron as root. Any processes spawned by the
task scheduler
inherit "SYSTEM" permissions. Using command line tools, we can kill the Windows
desktop (explorer.exe) and restart it running under "SYSTEM". Once running under
"SYSTEM" we have full control of the machine, and can do things even
Administrators
can't. Also included is a recommended fix. Read the full paper at the
link below.

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

Direct link to the original paper discussing this issue in detail...

http://www.pandora-security.com/forum/viewtopic.php?t=2093

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

Sincerely,

Daniel Hückmann - R&D Director, Pandora Security



Relevant Pages

  • Re: Windows Task Scheduler looses account credentials data
    ... You will now have a new Task Scheduler Log File. ... It can be checked by going to Start/Search and typing in: ... Accounts: Limit local account use of blank passwords to console logon only. ... How to Enable Automatic Logon in Windows ...
    (microsoft.public.windowsxp.general)
  • Re: ALC883 recording troubles...
    ... On Wed, Jun 11, 2008 at 8:00 PM, Daniel J Blueman ... I'm experiencing DC offset with the microphone on 2.6.24 (Ubuntu 8.04 ... Would it help to install windows, ...
    (Linux-Kernel)
  • Re: Do you use an OLD laptop as main PC? What do you use it for?
    ... Office 2000 isn't too bad on memory (better that Open Office, ... For REALLY LIGHT browsing, nothing beats Off-by-One on Windows (OK, ... Instead of the built in task scheduler, which I saw fail miserably on ... into System Scheduler tasks. ...
    (comp.sys.laptops)
  • Re: Windows Task Scheduler looses account credentials data
    ... You will now have a new Task Scheduler Log File. ... Accounts: Limit local account use of blank passwords to console logon ... How to Enable Automatic Logon in Windows ... or no account information existed for the task. ...
    (microsoft.public.windowsxp.general)
  • Re: Cant find server name
    ... Your Primary DNS Suffix is missing Daniel. ... > Ethernet adapter Local Area Connection: ... Linksys router will perform this function. ... doing this will lessen the load on your Windows machine and let the WIndows ...
    (microsoft.public.win2000.dns)