Privilege escalation in Windows Services for UNIX - CVE-2007-3036

 

Privilege escalation in Windows Services for UNIX - CVE-2007-3036

Published: December 16, 2016


Vulnerability identifier: #VU1357
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Green
CVE-ID: CVE-2007-3036
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Microsoft
Affected software:
Windows Services for UNIX

Detailed vulnerability description

The vulnerability allows a local user obtain elevated privileges on vulnerable system.

The vulnerability exists due to presence of certain setuid binary files on the system. A local user run certain setuid files and obtain elevated privileges on vulnerable system.

Successful exploitation of this vulnerability may allow a local user to obtain full access to vulnerable system.

Note: this vulnerability is being exploited in limited attacks.

How to mitigate CVE-2007-3036

Install security update from Microsoft website:

Windows 2000 Service Pack 4
Windows Services for UNIX 3.0
https://www.microsoft.com/downloads/details.aspx?FamilyId=557f89fc-c5d9-4405-9007-1654abf92277
Windows Services for UNIX 3.5
https://www.microsoft.com/downloads/details.aspx?FamilyId=70ae23c2-3ae8-4ea6-ba8d-8ac7e4f82663

Windows XP Service Pack 2
Windows Services for UNIX 3.0
https://www.microsoft.com/downloads/details.aspx?FamilyId=557f89fc-c5d9-4405-9007-1654abf92277
Windows Services for UNIX 3.5
https://www.microsoft.com/downloads/details.aspx?FamilyId=70ae23c2-3ae8-4ea6-ba8d-8ac7e4f82663

Windows Server 2003 Service Pack 1 and Windows Server 2003 Service Pack 2
Windows Services for UNIX 3.0
https://www.microsoft.com/downloads/details.aspx?FamilyId=557f89fc-c5d9-4405-9007-1654abf92277
Windows Services for UNIX 3.5
https://www.microsoft.com/downloads/details.aspx?FamilyId=70ae23c2-3ae8-4ea6-ba8d-8ac7e4f82663
Subsystem for UNIX-based Applications
https://www.microsoft.com/downloads/details.aspx?FamilyId=8ab5cc43-0b9c-45eb-aa51-47568ab6ce3f

Windows Server 2003 x64 Edition and Windows Server 2003 x64 Edition Service Pack 2
Subsystem for UNIX-based Applications
https://www.microsoft.com/downloads/details.aspx?FamilyId=1d21e3e8-b5f6-4044-9db6-054af836492b

Window Vista
Subsystem for UNIX-based Applications
https://www.microsoft.com/downloads/details.aspx?FamilyId=4d52e4f4-2888-42df-8163-85c648e65b29

Windows Vista x64 Edition
Subsystem for UNIX-based Applications
https://www.microsoft.com/downloads/details.aspx?FamilyId=4be667cc-c239-480b-a9a0-939bcd27f0de

Sources