DameWare Mini Remote Control Server...

- AV AC AU C I A
发布: 2003-08-11
修订: 2025-04-13

A vulnerability has been discovered in DameWare Mini Remote Control Server that could allow an unprivileged Windows user to gain SYSTEM privileges. The problem lies in the fact that DameWare Mini Remote Control Server runs with a window that has SYSTEM privileges, which is accessible by an unprivileged user. Due to a flaw in the Windows Messaging Subsystem, an attacker could exploit this issue by sending a malformed message to the target window, effectively triggering the execution of previously supplied instructions. It has been discovered that this issue only affects DMRCS when implementing specific client configurations. This vulnerability affects DWMRCS versions prior to 3.71.0.0. It should be noted that this BID previously stated that this issue was addressed in 3.70.0.0, which was incorrect.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息