Executive brief
A vulnerability in Windows NT allows local users to gain unauthorized privileges by tricking the system into running malicious code. Because the operating system automatically looks for programs in the current folder before searching system folders, a user can place a malicious file with a common name (like a system utility) in a shared folder. When an administrator or another user attempts to run the legitimate program while in that folder, the malicious version is executed instead, potentially compromising the entire system.
Technical details
The vulnerability stems from the search order used by the Windows API (specifically CreateProcess) and the command shell when resolving executable names. By default, Windows NT searches the current working directory ('.') before searching the system directories or the directories listed in the PATH environment variable. A local attacker with write access to a directory can place a 'Trojan horse' executable with the same name as a common system utility (e.g., cmd.exe or net.exe). When a higher-privileged user executes that command from the compromised directory, the attacker's code runs with the victim's privileges. This is a design-level issue in how the OS handles executable resolution.
Affected products
- Microsoft Windows NT 4.0 and earlier
Timeline
- 1997-07-23: disclosed: Initial discussion on NTBugtraq mailing list
- 1997-07-25: advisory: NVD published date