Lucene search

K
cve[email protected]CVE-2001-0349
HistoryJul 27, 2001 - 4:00 a.m.

CVE-2001-0349

2001-07-2704:00:00
web.nvd.nist.gov
25
cve-2001-0349
windows 2000
telnet service
vulnerability
arbitrary command execution
named pipe
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.1 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.1%

Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability.

Affected configurations

NVD
Node
microsoftwindows_2000

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7.1 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

13.1%

Related for CVE-2001-0349