Vulnerability Name: | CVE-2001-1518 (CCN-7533) | ||||||||
Assigned: | 2001-11-12 | ||||||||
Published: | 2001-11-12 | ||||||||
Updated: | 2019-04-30 | ||||||||
Summary: | RunAs (runas.exe) in Windows 2000 only creates one session instance at a time, which allows local users to cause a denial of service (RunAs hang) by creating a named pipe session with the authentication server without any request for service. Note: the vendor disputes this vulnerability, however the vendor also presents a scenario in which other users could be affected if running on a Terminal Server. Therefore this is a vulnerability. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: BUGTRAQ Type: UNKNOWN 20011114 RE:Radix Research Reports RADIX1112200101, RADIX1112200102, and RADIX1112200103 Source: MITRE Type: CNA CVE-2001-1518 Source: BUGTRAQ Type: UNKNOWN 20011112 RADIX1112200103 Source: CCN Type: Team RADIX Research Report: RADIX1112200103 Denial of Service Vulnerability in Windows 2000 RunAs Service Source: XF Type: UNKNOWN win2k-runas-dos(7533) Source: CCN Type: Microsoft Corporation Web site Service Packs Source: CCN Type: OSVDB ID: 20221 Microsoft Windows 2000 runas.exe Named Pipe Single Thread DoS Source: BID Type: Exploit 3291 Source: CCN Type: BID-3291 Microsoft Windows 2000 RunAs Service Denial of Services Vulnerability Source: XF Type: UNKNOWN win2k-runas-dos(7533) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |