3 ms·
The Windows-specific 'vulnerability' is weird. For one, it's part of the uninstaller, which isn't a common scenario, and secondly... C:\Windows\Temp isn't even
by ntauthority 4y ago
The Windows-specific 'vulnerability' is weird. For one, it's part of the uninstaller, which isn't a common scenario, and secondly... C:\Windows\Temp isn't even writable by unprivileged users by default, it's not even readable by unprivileged users by default (on my relatively fresh Windows 11 system, at least).
- nicce 4y agoAt least on Windows 10 and multi-user installations everyone can access C:\Windows\Temp How do you define unprivileged?
- jve 4y agoOn my Windows 10 machine, I can't access C:\Windows\Temp as unprivileged user. It makes me press Continue, which will invoke admin rights to set privileges for that folder.
- saurik 4y agoThat's because you don't have the permission to list the contents of the folder, but you should have permission to create files in it.
- jve 4y agoTrue. Get-Acl C:\Windows\TEMP | select -ExpandProperty AccessToString CREATOR OWNER Allow 268435456 NT AUTHORITY\SYSTEM Allow ReadData, Synchronize NT AUTHORITY\SYSTEM Allow 268435456 NT AUTHORITY\SYSTEM Allow FullControl BUILTIN\Administrators Allow 268435456 BUILTIN\Administrators Allow FullControl BUILTIN\Users Allow CreateFiles, AppendData, ExecuteFile, Synchronize BUILTIN\IIS_IUSRS Allow ReadData, Synchronize
- logbiscuitswave 4y agoThe thing about c:\windows\temp is you can’t modify another user’s files but you can create your own. It’s actually a _really_ common vector to exploit poorly written installers by dropping your own file (like a malicious dll or exe) into that directory as a low rights user in the hope that the high rights installer process will then load that code. That’s presumably what’s happening in this case.
- riedel 4y agoBoth vulnerabilities are reported as git for windows vulnerabilities, aren't they? I do not quite understand what is the 'correct' behaviour considering the parent directory thing. The concrete problem seems rather than that there is no -safe switch to use in prompts, etc.