fortypoundhead.com

Stopping the KnownDLLs Vulnerability

Posted On 2007-05-03 by FortyPoundHead
Keywords: Stopping the KnownDLLs Vulnerability
Tags:  Windows NT Windows 2000
Views: 2383


In Windows NT, core operating system DLLs are kept in virtual memory and shared between the programs running on the system. This has exposed a vulnerability that could allow a user to gain administrative privileges on the computer the user is interactively logged onto.
To enable stronger protection on system base objects such as the KnownDLLs list, change the value of 'ProtectionMode' to equal '1' in the registry key below.

Key: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager]
Value Name: ProtectionMode
Data Type: REG_DWORD
Data: (0 = disabled, 1 = enabled)

More Info: http://support.microsoft.com/support/kb/articles/q218/4/73.asp


About the Author

FortyPoundHead has posted a total of 1974 articles.

 


Comments On This Post

No comments on this post yet!


Do you have a thought relating to this post? You can post your comment here. If you have an unrelated question, you can use the Q&A section to ask it.

Or you can drop a note to the administrators if you're not sure where you should post.


Your IP address is:54.80.10.30

Before you can post, you need to prove you are human. If you log in, this test goes away.



Recent Forum Posts

New security implemented
dwirch posted on July 23, 2017 at about 6:58 in Site News

Fold Code Manager into main KB?
VB6Boy posted on July 22, 2017 at about 14:42 in Site News

Fold Code Manager into main KB?
dwirch posted on July 22, 2017 at about 14:41 in Site News

Fold Code Manager into main KB?
dwirch posted on July 21, 2017 at about 22:46 in Site News

Fold Code Manager into main KB?
dwirch posted on July 20, 2017 at about 7:55 in Site News

Job Spammer: Sam Mallon
dwirch posted on July 18, 2017 at about 18:36 in Spammers