ActiveSync can access a locked workstation w/o unlocking

From: Jeff.Samples (Jeff.Samplesat_private)
Date: Mon Apr 16 2001 - 05:05:49 PDT

  • Next message: Mark (Mookie): "Re: multiple vulnerabilities in Alcatel Speed Touch DSL modems"

    Microsoft was notified on 3/28/2001, you may use my name when publishing
    this. I cannot register on your site, so I am trying the general e-mail
    addresses.
    
    Platforms tested:
    ===================================================
    Microsoft Windows 2000 Professional (build 2195) w/ SP1
    Microsoft ActiveSync 3.1 (tested using HP Jornada 540 Series running Windows
    PocketPC (CE v 3.0.948 Build 9357)
    
    Issue:
    ===================================================
    MS ActiveSync can access files (Outlook appts, contacts, synced files, etc)
    from a Win2K workstation even though the workstation has been locked.  By
    simply dropping the HP into the dock, or hooking it up to the COM
    port(depending on which sync method is configured), it will sync and
    download data from a "locked" workstation. Yikes!
    
    Jeffrey A. Samples,
    Vice President, Product Development
    TERRADON Communications Group
    <http://www.terradoncommunications.com/>
    ph. - 304.755.1324
    fx. - 304.755.8274
    



    This archive was generated by hypermail 2b30 : Mon Apr 16 2001 - 12:51:35 PDT