Lucene search

K
cve[email protected]CVE-2001-1302
HistorySep 01, 2004 - 4:00 a.m.

CVE-2001-1302

2004-09-0104:00:00
web.nvd.nist.gov
29
windows 2000
password security
netuserchangepassword function
cve-2001-1302

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

7.2 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

47.5%

The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring error messages, possibly due to a problem in the NetuserChangePassword function.

Affected configurations

NVD
Node
microsoftwindows_2000
OR
microsoftwindows_2000sp1
OR
microsoftwindows_2000sp2

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

7.2 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

47.5%

Related for CVE-2001-1302