CVE-2004-2730

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
31/12/2004
Last modified:
03/04/2025

Description

Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSuspend before 1.05, and (10) PsShutdown before 2.32, does not properly disconnect from remote IPC$ and ADMIN$ shares, which allows local users to access the shares with elevated privileges by using the existing share mapping.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:psexec:*:*:*:*:*:*:*:* 1.53 (including)
cpe:2.3:a:microsoft:psgetsid:*:*:*:*:*:*:*:* 1.40 (including)
cpe:2.3:a:microsoft:psinfo:*:*:*:*:*:*:*:* 1.60 (including)
cpe:2.3:a:microsoft:pskill:*:*:*:*:*:*:*:* 1.02 (including)
cpe:2.3:a:microsoft:pslist:*:*:*:*:*:*:*:* 1.25 (including)
cpe:2.3:a:microsoft:psloglist:*:*:*:*:*:*:*:* 2.50 (including)
cpe:2.3:a:microsoft:pspasswd:*:*:*:*:*:*:*:* 1.20 (including)
cpe:2.3:a:microsoft:psservice:*:*:*:*:*:*:*:* 2.11 (including)
cpe:2.3:a:microsoft:psshutdown:*:*:*:*:*:*:*:* 2.31 (including)
cpe:2.3:a:microsoft:pssuspend:*:*:*:*:*:*:*:* 1.04 (including)
cpe:2.3:a:microsoft:sysinternals_pstools:*:*:*:*:*:*:*:* 2.04 (including)