Lucene search

K
cve[email protected]CVE-2001-0350
HistoryJul 27, 2001 - 4:00 a.m.

CVE-2001-0350

2001-07-2704:00:00
web.nvd.nist.gov
23
microsoft
windows 2000
telnet
local user
command execution
vulnerability
cve-2001-0350
nvd

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

7.1 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.0%

Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability.

Affected configurations

NVD
Node
microsoftwindows_2000

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

7.1 High

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.0%

Related for CVE-2001-0350