Security Basics mailing list archives

ActivX execution with PowerUser Privilege


From: "Marco Spennato" <m.spennato () resi it>
Date: Wed, 16 Nov 2005 00:07:55 +0100

Hi list,

I hope someone can help me to fix this problem...so I have an enterprise
environment, where some applications are provided to the users via web. The
environment is totally Microsoft, with an Active Directory forest and
Windows2000/XP clients.

Well, all the customers are "Power Users" on their workstations. I need to
enable a "one time" installation of an ActivX from the intranet portal,
without any privilege escalation on the workstation and/or on the user
account.
Now an administrator has to login with a major privilege, exec the
installation of the ActivX and then logoff.and it don't look pretty nice!
Any idea on how fix it? My best would be to authorize the first installation
without changing privileges on final user's account...


Any idea on workarounds?

 

Thanks in advance

Marco



Current thread: