MEDIUM · 4.6

CVE-2004-2730

Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsP...

Vulnerability Description

Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSuspend before 1.05, and (10) PsShutdown before 2.32, does not properly disconnect from remote IPC$ and ADMIN$ shares, which allows local users to access the shares with elevated privileges by using the existing share mapping.

CVSS Score

4.6

MEDIUM

AV:L/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
MicrosoftPsexec<= 1.53
MicrosoftPsgetsid<= 1.40
MicrosoftPsinfo<= 1.60
MicrosoftPskill<= 1.02
MicrosoftPslist<= 1.25
MicrosoftPsloglist<= 2.50
MicrosoftPspasswd<= 1.20
MicrosoftPsservice<= 2.11
MicrosoftPsshutdown<= 2.31
MicrosoftPssuspend<= 1.04
MicrosoftSysinternals Pstools<= 2.04

Related Weaknesses (CWE)

References

FAQ

What is CVE-2004-2730?

CVE-2004-2730 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsP...

How severe is CVE-2004-2730?

CVE-2004-2730 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-2730?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Psexec, Microsoft Psgetsid, Microsoft Psinfo, Microsoft Pskill, Microsoft Pslist.