GetAdmin patch not applied

Risk Level: High risk vulnerability  High

Check or Attack Name: getadmin

Platforms: Windows NT
Description:

The version of Windows NT is vulnerable to the GetAdmin exploit, allowing a local user to obtain administrator privileges by running getadmin.

Remedy:

To apply the latest Windows NT 4.0 Service Pack, follow these steps:

  1. Open a web browser.
  2. Go to http://support.microsoft.com/support/ntserver/Content/ServicePacks/ and follow the directions to download the appropriate service pack for your computer.
  3. Find the installation program you downloaded to your computer.
  4. Double-click the program icon to start the installation.
  5. Follow the installation directions.

—OR—

Windows NT 4.0 SP3 users must apply the post-SP3 getadmin patch. For the patch and the Knowledge Base Article, see ftp://ftp.microsoft.com/bussys/winnt/winnt-public/fixes/usa/nt40/hotfixes-postSP3/getadmin-fix/.

References:

Microsoft Knowledge Base Article Q146965, GetAdmin Utility Grants Users Administrative Rights, http://support.microsoft.com/support/kb/articles/q146/9/65.asp


X-Force Logo
Know Your Risks