CVE-2000-0155: Code Injection

Published Feb 18, 2000
·
Updated

Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alternate program to execute when other users access a drive.

Affected Software

3 affected components
Microsoft Windows NT=4.0
Microsoft Windows 95
Microsoft Windows 98=gold

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Disable Autorun so Windows NT does not execute autorun.inf files on non-removable (fixed) drives.

    Windows NT Autorun execute autorun.inf on non-removable media = disabled
  2. Configuration

    Disable Autorun so Windows 9x does not execute autorun.inf files on non-removable (fixed) drives.

    Windows 9x Autorun execute autorun.inf on non-removable media = disabled
  3. Compensating control

    Restrict write access to non-removable drives to trusted users (apply file system permissions or other access controls) to prevent untrusted users from placing autorun.inf files.

  4. Operational

    Search non-removable drives for autorun.inf files and remove or inspect any that specify alternate programs; remediate or remove unauthorized autorun.inf files.

Event History

Feb 18, 2000
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 23, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2000-0155?

CVE-2000-0155 is considered a moderate severity vulnerability due to the potential for local attack exploitation.

2

How do I fix CVE-2000-0155?

To remediate CVE-2000-0155, disable autorun functionality or restrict write permissions on non-removable media.

3

Which systems are affected by CVE-2000-0155?

CVE-2000-0155 affects Windows NT 4.0, Windows 95, and Windows 98 operating systems.

4

What type of attack does CVE-2000-0155 enable?

CVE-2000-0155 allows local attackers to execute a program of their choosing via the autorun.inf file.

5

Is CVE-2000-0155 remote or local vulnerability?

CVE-2000-0155 is a local vulnerability that requires physical access to the system.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203