The information in this article applies to:
SYMPTOMS
On a shared computer, it may be possible for a user to create a folder in the %SystemRoot\Recycler folder that is then assigned to another user based on the Security Identifier (SID) number. If you do this, a malicious user may assign themselves extended rights to the newly created Recycle Bin folder before it is assigned to another user. RESOLUTION
A supported fix that corrects this problem is now available from Microsoft, but it has not been fully regression tested and should be applied only to systems experiencing this specific problem. If you are not severely affected by this specific problem, Microsoft recommends that you wait for the next that contains this fix. Q248399i.exe for Intel-based computers Q248399a.exe for Alpha-based computersThe English-language version of this fix should have the following file attributes or later: For more information about how to download files from the Microsoft
Download Center, please visit the Download Center at the following Web
address
http://www.microsoft.com/downloads/search.aspand then click How to use the Microsoft Download Center. STATUSMicrosoft has confirmed this to be a problem in Windows NT 4.0. MORE INFORMATION
The Windows NT Recycle Bin for a user maps to a folder in
%SystemRoot%\Recycler. The name of the folder is based on the owner’s SID. The folder is created the first time the user deletes a file, and the owner is given the only permissions to it. However, if a malicious user can create the folder before the real one is created, that user could assign permissions that give them the ability to delete files from it or add files to it.
http://www.microsoft.com/security/bulletins/ms00-007faq.aspFor additional security-related information about Microsoft products, please visit the following Microsoft Web site: http://www.microsoft.com/security/ Additional query words:
Keywords : kbenv ntsecurity kbbug4.00 kbfix4.00 |
Last Reviewed: February 1, 2000 © 2000 Microsoft Corporation. All rights reserved. Terms of Use. |