Jump to content

RPC on local machine


Recommended Posts

Guest FromTheRafters
Posted

Just to satisfy my curiosity, would it have been possible to leverage

the MS08-067 flaw for privilege escalation on the local machine?

  • 2 weeks later...
  • Replies 2
  • Created
  • Last Reply
Guest Anteaus
Posted

Yes.

 

 

"FromTheRafters" wrote:

<span style="color:blue">

> Just to satisfy my curiosity, would it have been possible to leverage

> the MS08-067 flaw for privilege escalation on the local machine?

>

>

> </span>

Guest FromTheRafters
Posted

Thanks Anteaus, but this site indicates otherwise. Are they indeed wrong

about this? It wouldn't surprise me.

 

http://www.ca.com/us/securityadvisor/vulni...n.aspx?id=36809

 

I've read that RPC calls that don't specify a net address are assumed to

be local and I wonder if demarshalling and canonicalization are still

performed on these requests leading to exploit by specially crafted

requests.

 

"Anteaus" <Anteaus@discussions.microsoft.com> wrote in message

news:651825FD-C07F-4A29-AFB2-F7599257B247@microsoft.com...<span style="color:blue">

> Yes.

>

>

> "FromTheRafters" wrote:

><span style="color:green">

>> Just to satisfy my curiosity, would it have been possible to leverage

>> the MS08-067 flaw for privilege escalation on the local machine?

>>

>>

>> </span></span>

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...