Inappropriate user with Replace a Process Level Token privilege |
---|
Risk Level: | High | Check or Attack Name: Replace Process Token Privilege |
---|---|---|
Platforms: | Windows NT | |
Description: | A user has been detected with Replace a Process Level Token privileges. This right is not normally granted to any users, and can be used to attain administrative rights. |
|
Remedy: | Verify Advanced user rights in User Manager. To audit and revoke this privilege, follow these steps:
|
|
References: | Microsoft Knowledge Base Article Q101366, Definition and List of Windows NT Advanced User Rights, http://support.microsoft.com/support/kb/articles/q101/3/66.asp Microsoft Knowledge Base Article Q186374, Enable Auditing of Microsoft Windows NT Server Password Registry, http://support.microsoft.com/support/kb/articles/q186/3/74.asp Microsoft Knowledge Base Article Q131144, HOWTO: Assign Privileges to Accounts for API Calls, http://support.microsoft.com/support/kb/articles/q131/1/44.asp |
Know Your Risks |