Vulnerabilities > CVE-2004-0894 - Unspecified vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 26 |
Exploit-Db
description | MS Windows Improper Token Validation Local Exploit (working). CVE-2004-0894. Local exploit for windows platform |
id | EDB-ID:749 |
last seen | 2016-01-31 |
modified | 2005-01-11 |
published | 2005-01-11 |
reporter | Cesar Cerrudo |
source | https://www.exploit-db.com/download/749/ |
title | Microsoft Windows - Improper Token Validation Local Exploit |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS04-044.NASL |
description | The remote host is running version of the NT kernel and LSASS which could allow a local user to gain elevated privileged. An attacker who has the ability to execute arbitrary commands on the remote host could exploit these flaws to gain SYSTEM privileges. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15963 |
published | 2004-12-14 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15963 |
title | MS04-044: Vulnerabilities in Windows Kernel and LSASS (885835) |
code |
|
Oval
accepted 2005-02-23T09:25:00.000-04:00 class vulnerability contributors name Christine Walzer organization The MITRE Corporation description LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program. family windows id oval:org.mitre.oval:def:1888 status accepted submitted 2005-01-04T12:00:00.000-04:00 title LSASS Privilege Escalation Vulnerability (64-bit Server 2003) version 65 accepted 2011-05-16T04:02:22.067-04:00 class vulnerability contributors name Christine Walzer organization The MITRE Corporation name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program. family windows id oval:org.mitre.oval:def:2062 status accepted submitted 2005-01-04T12:00:00.000-04:00 title LSASS Privilege Escalation Vulnerability (64-bit XP, SP1) version 68 accepted 2005-02-23T09:25:00.000-04:00 class vulnerability contributors name Ingrid Skoog organization The MITRE Corporation description LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program. family windows id oval:org.mitre.oval:def:3312 status accepted submitted 2005-01-05T12:00:00.000-04:00 title LSASS Privilege Escalation Vulnerability (Server 2003/64-bit XP) version 65 accepted 2011-05-16T04:02:44.893-04:00 class vulnerability contributors name Christine Walzer organization The MITRE Corporation name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program. family windows id oval:org.mitre.oval:def:3325 status accepted submitted 2004-12-28T12:00:00.000-04:00 title LSASS Privilege Escalation Vulnerability (32-bit XP, SP1) version 68 accepted 2011-05-16T04:02:57.789-04:00 class vulnerability contributors name Christine Walzer organization The MITRE Corporation name Dragos Prisaca organization Gideon Technologies, Inc. name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program. family windows id oval:org.mitre.oval:def:4368 status accepted submitted 2004-12-28T12:00:00.000-04:00 title LSASS Privilege Escalation Vulnerability (32-bit XP, SP2) version 69 accepted 2011-05-16T04:03:27.063-04:00 class vulnerability contributors name Christine Walzer organization The MITRE Corporation name Andrew Buttner organization The MITRE Corporation name Shane Shaffer organization G2, Inc. name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program. family windows id oval:org.mitre.oval:def:778 status accepted submitted 2004-12-28T12:00:00.000-04:00 title LSASS Privilege Escalation Vulnerability (Windows 2000) version 70
References
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-044
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18340
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1888
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2062
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3312
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3325
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4368
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A778