PT-2001-2602 · Microsoft · Runas.Exe+1
Published
2001-12-31
·
Updated
2024-08-08
·
CVE-2001-1517
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Windows 2000
Description
The issue concerns the storage of cleartext authentication information in memory by RunAs (runas.exe) in Windows 2000. This could potentially allow attackers to obtain usernames and passwords by executing a process allocated the same memory page after a RunAs command terminates. It is noted that the vendor disputes this issue, stating that administrative privileges are already required to exploit it.
Recommendations
For Windows 2000, consider restricting access to the
runas.exe command to minimize the risk of exploitation, as administrative privileges are required to exploit this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows 2000
Runas.Exe