DCOM launch permission incorrect |
---|
Risk Level: | Medium | Check or Attack Name: DCOM Launch Permission |
---|---|---|
Platforms: | Windows NT | |
Description: | Launch permissions on the DCOM object allow non-administrators to launch DCOM objects and execute code on the host. False Positives: If a DCOM object implements internal security measures, then this issue is not a vulnerability. |
|
Remedy: | Fortify the DCOM object's permissions so that it continues to function under tightened security:
|
|
References: | Microsoft Knowledge Base Article Q176799, INFO: Using DCOM Config (DCOMCNFG.EXE) on Windows NT, http://support.microsoft.com/support/kb/articles/q176/7/99.asp |
Know Your Risks |