source: wwwsecurityfocuscom/bid/645/info
Any authenticated NT user (ie domain user) can modify the pathname for the RASMAN binary in the Registry The next time the RAS Service is started, the (trojan) service referenced by the RASMAN pathname will be executed with system privileges This trojan service may allow the User to execute comma ...