Executive brief
A configuration issue in Windows NT allows standard users to be granted excessive administrative privileges. This could allow an individual with local access to perform sensitive actions such as bypassing security audits, modifying system files, or taking ownership of data they should not be able to access. Such misconfigurations can lead to a total compromise of the workstation or server's integrity and confidentiality.
Technical details
This vulnerability describes a state of excessive privilege assignment within the Windows NT operating system. Users may be granted sensitive rights including, but not limited to, 'Act as part of the operating system', 'Debug programs', 'Take ownership of files or other objects', and 'Load and unload device drivers'. An attacker with local access and these privileges can bypass security descriptors, escalate their authority to SYSTEM level, or interfere with kernel-mode operations. The root cause is typically insecure default configurations or administrative errors in User Rights Assignment. Remediation involves auditing and restricting user rights via the User Manager or Group Policy to follow the principle of least privilege.
Affected products
- Microsoft Windows NT
Timeline
- 1997-01-01: disclosed