Stopping the KnownDLLs Vulnerability
In Windows NT, core operating system DLLs are kept in virtual memory and shared between the programs running on the system. This has exposed a vulnerability that could allow a user to gain administrative privileges on the computer the user is interactively logged onto.
To enable stronger protection on system base objects such as the KnownDLLs list, change the value of 'ProtectionMode' to equal '1' in the registry key below.
Key: [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager]
Value Name: ProtectionMode
Data Type: REG_DWORD
Data: (0 = disabled, 1 = enabled)
More Info: http://support.microsoft.com/support/kb/articles/q218/4/73.asp
Loading Comments ...
Comments
No comments have been added for this post.
You must be logged in to make a comment.