H
HF
I read from http://technet.microsoft.com/en-us/library/bb456992.aspx that
"limited user accounts cannot stop or start services" and I can see why
that's a very good thing for security. But then I started looking around and
found that on my system limited users can't start or stop most services, but
can start certain services, and I'm wondering if that's normal or a security
issue?
For example, as a limited user I can't stop the Print Spooler service that
is set to automatic. That's ok. But, I can start the Portable Media Serial
Number service that is set to manual as a limited user! Strangely I can't
stop it as a limited user once it's started, it has to stop on its own. Also
I can start the Application Management service as a limited user.
Is this a problem? Should a limited user be able to start these services?
Couldn't some virus load the service as a limited user and make it execute a
virus in admin privileges since it's a service? Or is it normal that limited
users can start those services and they couldn't be used to do anything bad
like get admin privileges for some virus or hacker?
Thank you =)
"limited user accounts cannot stop or start services" and I can see why
that's a very good thing for security. But then I started looking around and
found that on my system limited users can't start or stop most services, but
can start certain services, and I'm wondering if that's normal or a security
issue?
For example, as a limited user I can't stop the Print Spooler service that
is set to automatic. That's ok. But, I can start the Portable Media Serial
Number service that is set to manual as a limited user! Strangely I can't
stop it as a limited user once it's started, it has to stop on its own. Also
I can start the Application Management service as a limited user.
Is this a problem? Should a limited user be able to start these services?
Couldn't some virus load the service as a limited user and make it execute a
virus in admin privileges since it's a service? Or is it normal that limited
users can start those services and they couldn't be used to do anything bad
like get admin privileges for some virus or hacker?
Thank you =)