First published: Tue Feb 15 2000(Updated: )
The installation for Windows 2000 does not activate the Administrator password until the system has rebooted, which allows remote attackers to connect to the ADMIN$ share without a password until the reboot occurs.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2000 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0222 is considered a critical vulnerability due to the risk of unauthorized access to the ADMIN$ share without a password until the system reboot.
To mitigate CVE-2000-0222, ensure that the Windows 2000 system is rebooted after installation to activate the Administrator password.
CVE-2000-0222 affects all installations of Microsoft Windows 2000 that have not yet been rebooted post-installation.
Exploiting CVE-2000-0222 could allow remote attackers to access privileged shares and potentially gain control over the affected Windows 2000 system.
A simple workaround for CVE-2000-0222 is to set a strong Administrator password before rebooting the system after installation.