PT-2005-3991 · Microsoft · Windows 2000
Published
2005-10-06
·
Updated
2008-09-05
·
CVE-2005-3169
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows 2000 versions before Update Rollup 1 for SP4
Description
The issue concerns the failure to record a specific event message in the security event log when the "audit directory service access" policy is enabled. This could potentially allow attackers to conduct unauthorized activities without detection, specifically regarding File Delete Child operations on an Active Directory object.
Recommendations
For Microsoft Windows 2000 versions before Update Rollup 1 for SP4, apply Update Rollup 1 for SP4 to address the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows 2000