<<< Date Index >>>     <<< Thread Index >>>

Trend Officescan local privilege escalation



Product:              Trend OfficeScan
Product Description: Trend OfficeScan is a Corporate Antivirus product from Trend Microsystems
Versions affected:    Tested on 5.5 (others may be vulnerable)
Vulnerability type:   Local privilege escalation
Vendor URL:           http://www.trendmicro.com
OS tested             Windows XP + SP1 (others may be vulnerable)
Vendor notified:      10th May 2004
Initial response:     11th May 2004
Patch available:      2nd June 2004
Patch: http://uk.trendmicro-europe.com/enterprise/support/knowledge_base_detail.php?solutionId=20118

Details:
When Trend OfficeScan detects a virus, the "OfficeScan Client" window is displayed with information regarding the virus found. This Window is owned by the "OfficeScanNT RealTime Scan" service (ntrtscan.exe). Clicking the help button on this OfficeScan Client window starts winhlp32.exe using the same account as the OfficeScan service. This sevice is started with local SYSTEM account by default.

From the winhlp32 file+open explorer window it is simple to start any
application with the inherited rights of the Officescan service account.

To test the vulnerability:

- Use the eicar test virus[1] to display the OfficeScan Client Window
- Click the help button
- Start task manager and make sure that the "User name" Column is visible.
- find the "winhlp32.exe" process in the list
- check the user name for winhlp32.exe

If the computer is vulnerable the winhlp32.exe will be running with the same account as the OfficeScanNT RealTime Scan service.

[1] http://www.eicar.org/anti_virus_test_file.htm

Regards, Donald Reid

donald_reid[at]hotmail.com

_________________________________________________________________
It's fast, it's easy and it's free. Get MSN Messenger today! http://www.msn.co.uk/messenger