Microsoft Windows Server 2008 R2 Permissions on New Cluster Disks Vulnerability ( 13 October 2010 )
RISK: Medium Risk
A tampering vulnerability exists in the way the Failover Cluster Manager user interface handles permissions on shared cluster disks. This vulnerability exists because the Failover Cluster Manager uses unsecured default permissions when adding disks to a cluster. When an administrator adds a disk to a shared cluster, the Failover Cluster Manager sets permissions on the shared cluster disk in a way that potentially provides unauthorized users (everyone) with read/write/delete access to the administrative shares on the failover cluster disk.
Impact
- Data Manipulation
System / Technologies affected
- Windows Server 2008 R2
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
Download locations for this patch
Vulnerability Identifier
Source
Related Link
Share with