Executive brief
A security configuration issue in Windows NT allows users without administrative privileges to access the system registry over the network. The registry is a critical database that stores configuration settings for the operating system and installed applications. Unauthorized access could allow an attacker to view sensitive system information or modify settings, potentially leading to a full system compromise or service disruption.
Technical details
This vulnerability stems from insecure default permissions on the Windows NT registry that allow remote access via RPC/named pipes to non-administrative users. An attacker with network connectivity to the target system can remotely connect to the registry hive without requiring administrative credentials. This allows for the unauthorized reading and writing of registry keys, which can be leveraged to extract sensitive system data, alter security policies, or achieve remote code execution by modifying startup parameters. The issue is primarily addressed by restricting the 'winreg' interface and hardening registry ACLs.
Affected products
- Microsoft Windows NT All versions prior to fix
Timeline
- 1997-01-01: disclosed: Initial NVD publication date