CVE-2004-2730
Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9)…
Does this matter?
Lower severity and a low EPSS score (1.51%). Track it; it rarely justifies an emergency change on its own.
Description
Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSuspend before 1.05, and (10) PsShutdown before 2.32, does not properly disconnect from remote IPC$ and ADMIN$ shares, which allows local users to access the shares with elevated privileges by using the existing share mapping.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.51% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- microsoft/psexec · microsoft/psgetsid · microsoft/psinfo · microsoft/pskill · microsoft/pslist · microsoft/psloglist · microsoft/pspasswd · microsoft/psservice · microsoft/psshutdown · microsoft/pssuspend · microsoft/sysinternals pstools
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/12108Vendor Advisory
- http://securitytracker.com/id?1010737
- http://www.osvdb.org/8140
- http://www.securityfocus.com/bid/10759Patch
- http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=28304
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16743
- http://secunia.com/advisories/12108Vendor Advisory
- http://securitytracker.com/id?1010737
- http://www.osvdb.org/8140
- http://www.securityfocus.com/bid/10759Patch
- http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=28304
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16743
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.