PT-2001-1573 · Microsoft · Windows 2000
Publicado
2001-07-21
·
Atualizado
2018-10-12
·
CVE-2001-0350
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows 2000
Description
The issue concerns the Microsoft Windows 2000 telnet service, which creates named pipes with predictable names and fails to properly verify them. This allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it.
Recommendations
For Microsoft Windows 2000, consider restricting access to the telnet service until a fix is available. As a temporary workaround, avoid using the telnet service for executing commands. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Windows 2000