Title: NT Clipboard Available To Unauthenticated Users Vulnerability
Severity: LOW
Description:
Users may paste information to the Windows clipboard in a variety of ways: CTL-C, edit cut, edit copy, etc. This information remains in the clipboard until it is maually cleared or the machine is shutdown.
When a user secures his or her desktop by pressing ctl-alt-del then enter, or when a password protected screensaver becomes active, the user assumes their host and their data to be secure from access at the local console.
Data stored in the clipboard can still be accessed even thought the console is locked. Pressing ctl-alt-del will invoke the logon window. Instead of typing the users name, the clipboard data can be displayed by pressing ctl-v while the cursor is in the username or password window.
Jason Adam Young <jason_young@NCSU.EDU> posted to NTBugtraq and expressed concern that Microsoft may not have fixed the problem by simply releasing an update GINA. Instead, he feels that the problem lies within the Clipboard and its interaction with the WindowStation system object.
Affected Products:
- Microsoft Windows NT 3.5.1 SP1
- Microsoft Windows NT 3.5.1 SP2
- Microsoft Windows NT 3.5.1 SP3
- Microsoft Windows NT 3.5.1 SP4
- Microsoft Windows NT 3.5.1 SP5
- Microsoft Windows NT 4.0
- Microsoft Windows NT 4.0 SP1
- Microsoft Windows NT 4.0 SP2
- Microsoft Windows NT 4.0 SP3
- Microsoft Windows NT 4.0 SP4
- Microsoft Windows NT Enterprise Server 4.0
- Microsoft Windows NT Enterprise Server 4.0 SP1
- Microsoft Windows NT Enterprise Server 4.0 SP2
- Microsoft Windows NT Enterprise Server 4.0 SP3
- Microsoft Windows NT Enterprise Server 4.0 SP4
- Microsoft Windows NT Server 4.0
- Microsoft Windows NT Server 4.0 SP1
- Microsoft Windows NT Server 4.0 SP2
- Microsoft Windows NT Server 4.0 SP3
- Microsoft Windows NT Server 4.0 SP4
- Microsoft Windows NT Terminal Server 4.0
- Microsoft Windows NT Terminal Server 4.0 SP1
- Microsoft Windows NT Terminal Server 4.0 SP2
- Microsoft Windows NT Terminal Server 4.0 SP3
- Microsoft Windows NT Terminal Server 4.0 SP4
- Microsoft Windows NT Workstation 4.0
- Microsoft Windows NT Workstation 4.0 SP1
- Microsoft Windows NT Workstation 4.0 SP2
- Microsoft Windows NT Workstation 4.0 SP3
- Microsoft Windows NT Workstation 4.0 SP4
References:
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.