[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Get admin rights using Doro (pdf creator)
- To: bugtraq@securityfocus.com
- Subject: Get admin rights using Doro (pdf creator)
- From: Ramon Kukla <ml@portsonline.net>
- Date: Sun, 14 Dec 2003 22:06:41 +0100
Hi,
a few days ago i discovered a bug in Doro[1]. Doro is a free tool to
create pdf files from any windows program. After installing Doro you
have a new printer called 'Doro PDF Writer'.
If you select 'Print' the spooler calls the printer filter 'doro.dll'.
The 'doro.dll' then starts 'doro.exe' and a file requester appears.
I guess that most of you see the problem. The spooler is controlled by
the account 'system'. Therefore the file requester has the same rights.
It's easy now to create a new user and move them into the group
'admins'.
I informed the coder of the software and he approved the problem.
regards
Ramon
[1] http://www.geocities.com/the_real_sz/misc/doro.htm