Scheduler Key has incorrect permissions |
---|
Risk Level: | Medium | Check or Attack Name: scheduler permissions |
---|---|---|
Platforms: | Windows NT | |
Description: | The HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Schedule key controls the Schedule service. Server Operators have permission to write to this registry key that would allow them to manually schedule jobs to be run by the Schedule service. Since the Schedule service normally executes under the system user context, this vulnerability can be used to raise the Server OperatorÆs access level to Administrator. |
|
Remedy: | Remove Server operator write access to the schedule key in the NT registry. To remove write access, follow these steps:
|
|
References: |
Know Your Risks |