#VU48660 Security restrictions bypass in Windows and Windows Server
Published: November 26, 2020
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect permissions set for two registry keys for the RPC Endpoint Mapper and DNSCache services. A local user can modify keys a leverage behavior of other system services to load a malicious DLL and execute arbitrary code with SYSTEM privileges.
Affected registry keys are:
- HKLMSYSTEMCurrentControlSetServicesRpcEptMapper
- HKLMSYSTEMCurrentControlSetServicesDnscache
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.
As a remediation, change permissions on the registry keys and disable access to these keys for unprivileged users.