PT-2002-2168 · Microsoft · Windows 2000
Published
2002-11-12
·
Updated
2019-04-30
·
CVE-2002-1184
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Microsoft Windows 2000
Description:
The system root folder of Microsoft Windows 2000 has default permissions that allow the Everyone group to have Full access. This could enable attackers to gain privileges as other users via Trojan horse programs, as the system root folder is in the search path when locating programs during login or application launch from the desktop.
Recommendations:
For Microsoft Windows 2000, consider restricting the permissions of the Everyone group on the system root folder to minimize the risk of exploitation. As a temporary workaround, monitor the system for any suspicious activity and restrict the execution of programs from untrusted sources. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows 2000