The problem is caused due to the firewall by default accepting incoming connections to ports listened on by the “sessmgr.exe” process.
This can e.g. be exploited by malicious, unprivileged users to host an unauthorised service or by a trojan to accept incoming connections by starting “sessmgr.exe” and then inject malicious code into the running process.
Successful exploitation does not require administrative privileges on an affected system.
The weakness has been reported in Windows XP SP2. Other versions may also be affected.
Labot situāciju var ar sekojošām darbībām.
Uncheck “Remote Assistance” under the “Exceptions” tab for the ICF configuration.