Critical key permissions incorrect |
---|
Risk Level: | Medium | Check or Attack Name: Critical Key Permissions |
---|---|---|
Platforms: | Windows NT | |
Description: | A registry key that can lead to higher access levels is writable by non-administrators. Each of these keys can be used to insert a Trojan horse program that is then invoked when another user logs in. The AeDebug key can be used to directly gain higher access if the attacker can cause a service running at a privileged user level to crash. The vulnerable keys under HKEY_LOCAL_MACHINE are:
|
|
Remedy: | Set permissions on each of these keys. Grant Administrators and System users full access, and Everyone read access. To set key permissions, follow these steps:
|
|
References: |
Know Your Risks |