| VID |
28061 |
| Severity |
40 |
| Port |
139,445 |
| Protocol |
TCP |
| Class |
SMB |
| Detailed Description |
The SNMP registry key is writable by users who are not in the Administrators group. The SNMP protocol in Windows NT4 and 2000 enables an administrator to manage network devices remotely. The location of the SNMP parameters key is HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SNMP\Parameters. The SNMP parameters key in the registry stores community name and management station identifiers. Unfortunately this information is readable by all users, allowing malicious users to pose as a management station for any communities belonged to. The key settings are typically modified by a user with administrative privileges, due to a default configuration error the SNMP Registry Key permits any user, that is logged into that particular machine, to edit the settings. By editing the parameters key, a user could in theory create a new community with management privileges for themselves. Successful exploitation of this vulnerability could allow a attacker to gain full control of network devices and other resources managed via SNMP.
* Note: This check requires an account with Guest or upper privileges which can access the registry of the remote host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.
* References: http://www.microsoft.com/technet/security/bulletin/MS00-095.asp http://www.microsoft.com/technet/security/bulletin/MS00-096.asp http://www.ciac.org/ciac/bulletins/l-027.shtml http://www.ciac.org/ciac/bulletins/l-026.shtml
* Platforms Affected: Windows NT Any version Windows 2000 Any version |
| Recommendation |
Apply the patch for your system, as listed in Microsoft Security Bulletin MS00-095 at http://www.microsoft.com/technet/security/bulletin/MS00-095.asp
-- OR --
Remove write access to the SNMP registry key from users who are not in the Administrators group. This requires a modification in the registry as the following steps:
1. Open Registry Editor. From the Windows Start menu, select Run, type regedt32, and click OK. 2. Go to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SNMP\Parameters. 3. From the Security menu, select Permissions to display the Registry Key Permissions dialog box. 4. Remove or change any permissions such as Everyone - Full Control. And review any names with Full Control permissions and determine if the permission is appropriate. Originally, This registry key is set as the following permissions: - Administrators group : Full Control - SYSTEM : Full Control - Everyone : Read |
| Related URL |
CVE-2001-0046 (CVE) |
| Related URL |
2066 (SecurityFocus) |
| Related URL |
5672 (ISS) |
|