Windows NT rcmd service running

Risk Level: Low risk vulnerability  Low

Check or Attack Name: rcmd

Platforms: Windows NT
Description:

The Rcmd service was detected as running. This service allows users to execute command-line programs from remote hosts and is distributed in the Windows NT Resource Kit. Rcmd is known to be vulnerable to spoofing because it uses native Windows NT challenge-response authentication, instead of host-level authentication.

Remedy:

Remove the rcmd service.

To remove the rcmd services, follow these steps:

  1. Open the Services control panel. From the Windows NT Start menu, select Settings, Control Panel, Services.
  2. Under Services, select rcmd.
  3. Click Stop.
References:

X-Force Logo
Know Your Risks