[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-disclosure] Flaw in Microsoft Domain Account Caching Allows Local Workstation Admins to Temporarily Escalate Privileges and Login as Cached Domain Admin Accounts (2010-M$-002)



On Thu, Dec 9, 2010 at 10:07 PM, Thor (Hammer of God)
<thor@xxxxxxxxxxxxxxx> wrote:
> What do you mean by "regular local administrator"?  You're a local admin,
> or you're not.
I believe the OP's intent was to differentiate between Local
Administrators and Domain (or Enterprise) Administrators. Corrections
from StenoPlasma are welcomed.

> There are not degrees of local admin.
But there are different accounts, both domain and local, which have
administrator rights and privileges on the local machine.

[SNIP]

Jeff

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/