SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2004-2730

Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9)…

MEDIUM 4.6EPSS 1.51%

Does this matter?

Lower severity and a low EPSS score (1.51%). Track it; it rarely justifies an emergency change on its own.

Description

Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSuspend before 1.05, and (10) PsShutdown before 2.32, does not properly disconnect from remote IPC$ and ADMIN$ shares, which allows local users to access the shares with elevated privileges by using the existing share mapping.

CVSS 2.0
4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS
1.51% probability · 73th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
microsoft/psexec · microsoft/psgetsid · microsoft/psinfo · microsoft/pskill · microsoft/pslist · microsoft/psloglist · microsoft/pspasswd · microsoft/psservice · microsoft/psshutdown · microsoft/pssuspend · microsoft/sysinternals pstools
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.