Posted Friday 19th September 2008 16:02 GMT
All right, serious question: iTunes on Windows has Services; are priv elevations possible?
The iPodService.exe (sp?) service runs as LocalSystem and iTunesHelper.exe runs as the user currently logged on. These things probably communicate with each other.
Can this combination result in a privilege elevation exploit due to this or some other vulnerability? Because this would be a "critical" problem to me, as it could grant admin access to non-admins, and allow all sorts of abuse.
Opinion
David McLeman
My 25 years of comical IT buzzwords
Tim Worstall
Time to take a sniff at the coffee, perhaps
Chris Mellor
Will they have to drag him back like last time?
Popular Stories
Features
Playing the SLA long game
More than just middlemen...
Applications must work for the cloud to float
How a Unix killer crawled from the dot-com bust