« Volver al listado

CVE-2004-2730

Estado: ModificadaMedia (4.6)—

Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSuspend before 1.05, and (10) PsShutdown before 2.32, does not properly disconnect from remote IPC$ and ADMIN$ shares, which allows local users to access the shares with elevated privileges by using the existing share mapping.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (11)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2004-2730",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2004-12-31T05:00:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/12108",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1010737",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/8140",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/10759",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=28304",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/16743",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/12108",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1010737",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/8140",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/10759",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www3.ca.com/securityadvisor/vulninfo/vuln.aspx?id=28304",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/16743",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSuspend before 1.05, and (10) PsShutdown before 2.32, does not properly disconnect from remote IPC$ and ADMIN$ shares, which allows local users to access the shares with elevated privileges by using the existing share mapping."
    }
  ],
  "lastModified": "2026-06-16T22:10:14.357",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:microsoft:psexec:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A6C140D7-0DA3-453B-A06D-070DEBD943A0",
              "versionEndIncluding": "1.53"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:psgetsid:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4B9E0C2C-4BF7-4DBF-964E-F033943BEA73",
              "versionEndIncluding": "1.40"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:psinfo:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A550D0AA-1C64-4F47-BC34-50938AD19647",
              "versionEndIncluding": "1.60"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:pskill:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC22873C-3E90-48F8-A7A0-924B77E6E14C",
              "versionEndIncluding": "1.02"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:pslist:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "68257748-F761-445C-A656-0E9390AB4723",
              "versionEndIncluding": "1.25"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:psloglist:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "406120EC-5A6F-4C35-87CC-704A81276A01",
              "versionEndIncluding": "2.50"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:pspasswd:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "30C0566A-E0C8-48F8-AFAB-9B791E683FD3",
              "versionEndIncluding": "1.20"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:psservice:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0A29E57-7FED-43A7-8F2E-413D3A3DA08E",
              "versionEndIncluding": "2.11"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:psshutdown:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "292787CF-D353-44D3-BBFE-F61A693D2B79",
              "versionEndIncluding": "2.31"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:pssuspend:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A76A6F29-D9EA-4C09-91D1-4408EDB4965C",
              "versionEndIncluding": "1.04"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:sysinternals_pstools:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "026F39FC-E2B0-411C-A4D9-FC3DD0AC200D",
              "versionEndIncluding": "2.04"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}