Re: two questions that need answering

From: Bronek Kozicki (brok@rubikon.pl)
Date: 01/29/02


From: "Bronek Kozicki" <brok@rubikon.pl>
To: <focus-ms@securityfocus.com>
Date: Tue, 29 Jan 2002 10:09:52 +0100


> 2. Yes. You need to compile it with the nddeapi.lib linked. Then
you need
> to have NetDDE running. This can be a bit of a rub, since most "user"
> accounts don't have the privilege to start services. Then just run
the

This particular service (NetDDE) can be started by ordinary user. I
know, I have tested it, and gained LocalSystem privileges using this
exploit with no problem.

B.