DCOM access permission incorrect

Risk Level: Medium risk vulnerability  Medium

Check or Attack Name: DCOM Access Permission

Platforms: Windows NT
Description:

Access permissions on the DCOM object let non-administrators create DCOM objects and execute code on the local system.

Remedy:

Fortify the DCOM object's permissions so that it continues to function under tightened security:

  1. Run the dcomcnfg program in the %SystemRoot%/System32 folder.
  2. Double-click the DCOM object that generated this vulnerability.
  3. Click Security.
  4. Edit the access permissions. Some applications may require loose access permissions in order to function. Verify that the object in question still functions properly after making any changes.
  5. Click OK twice.
References:

Microsoft Knowledge Base Article Q176799, INFO: Using DCOM Config (DCOMCNFG.EXE) on Windows NT, http://support.microsoft.com/support/kb/articles/q176/7/99.asp


X-Force Logo
Know Your Risks