CVE-2004-2730
Sysinternals PsTools before 2.05, including (1) PsExec before 1.54, (2) PsGetsid before 1.41, (3) PsInfo before 1.61, (4) PsKill before 1.03, (5) PsList before 1.26, (6) PsLoglist before 2.51, (7) PsPasswd before 1.21, (8) PsService before 2.12, (9) PsSuspend before 1.05, and (10) PsShutdown before 2.32, does not properly disconnect from remote IPC$ and ADMIN$ shares, which allows local users to access the shares with elevated privileges by using the existing share mapping.
Published:Dec 31, 2004
Last Modified:Apr 16, 2026
EPS:Oct 9, 2007
EPSS Score:0.00919
CVSS Score:4.6
Affected Products
Vendor
Product
Action
Vendor
Microsoft
Product
Psexec
Microsoft
Psexec
Vendor
Microsoft
Product
Psgetsid
Microsoft
Psgetsid
Vendor
Microsoft
Product
Psinfo
Microsoft
Psinfo
Vendor
Microsoft
Product
Pskill
Microsoft
Pskill
Vendor
Microsoft
Product
Pslist
Microsoft
Pslist
Vendor
Microsoft
Product
Psloglist
Microsoft
Psloglist
Vendor
Microsoft
Product
Pspasswd
Microsoft
Pspasswd
Vendor
Microsoft
Product
Psservice
Microsoft
Psservice
Vendor
Microsoft
Product
Psshutdown
Microsoft
Psshutdown
Vendor
Microsoft
Product
Pssuspend
Microsoft
Pssuspend
Vendor
Microsoft
Product
Sysinternals Pstools
Microsoft
Sysinternals Pstools
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
