The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password" vulnerability.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/2133 | Exploit Patch Vendor Advisory |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-099 | |
http://www.securityfocus.com/bid/2133 | Exploit Patch Vendor Advisory |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-099 |
Configurations
History
20 Nov 2024, 23:34
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/2133 - Exploit, Patch, Vendor Advisory | |
References | () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-099 - |
Information
Published : 2001-02-12 05:00
Updated : 2024-11-20 23:34
NVD link : CVE-2001-0048
Mitre link : CVE-2001-0048
CVE.ORG link : CVE-2001-0048
JSON object : View
Products Affected
microsoft
- windows_2000
CWE