Microsoft Windows SMB Registry : Schedule Key Permission Weakness Local Privilege Escalation

This script is Copyright (C) 2000-2015 Tenable Network Security, Inc.


Synopsis :

Local users can elevate their privileges.

Description :

The registry key SYSTEM\CurrentControlSet\Services\Schedule is
writeable by users who are not in the admin group.

Since the scheduler runs with SYSTEM privileges, this allow a
malicious user to gain these privileges on this system.

Solution :

Use regedt32 and set the permissions of this key to :

- admin group : Full Control
- system : Full Control
- everyone : Read

Risk factor :

High / CVSS Base Score : 7.2
(CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C)

Family: Windows

Nessus Plugin ID: 10426 ()

Bugtraq ID:

CVE ID: CVE-1999-0589

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now