CVE-2000-0331: Buffer Overflow

Published Apr 20, 2000
·
Updated

Buffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long environment variable, aka the "Malformed Environment Variable" vulnerability.

Affected Software

3 affected components
Microsoft Terminal Server
Microsoft Windows 2000
Microsoft Windows NT=4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Restrict execution of cmd.exe to trusted/administrative accounts (for example, by tightening file ACLs on %SystemRoot%\system32\cmd.exe or using Group Policy) so unprivileged local users cannot invoke CMD.EXE and exploit the vulnerability.

    Microsoft Windows (cmd.exe) execute_permission = restricted to administrators
  2. Compensating control

    Prevent untrusted or unnecessary local logons to affected systems (Windows NT and Windows 2000). Enforce strict local logon restrictions, disable or remove unneeded accounts, and use host-based access controls or central policy to limit interactive/logon access to trusted administrators only.

  3. Operational

    Monitor vendor (Microsoft) advisories for this issue and apply any supplied patches or fixes as soon as they become available. In the meantime, audit hosts for unexpected use of CMD.EXE and review system crash/DoS indicators to detect exploitation attempts.

Event History

Apr 20, 2000
CVE Published
04:00 AM
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Jul 12, 2000
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2000-0331?

CVE-2000-0331 has a severity rating that indicates it can lead to denial of service due to potential system instability.

2

Who is affected by CVE-2000-0331?

CVE-2000-0331 affects local users of Microsoft Windows 2000 and Windows NT 4.0.

3

How do I fix CVE-2000-0331?

To mitigate CVE-2000-0331, it is recommended to apply the latest security patches provided by Microsoft for the affected operating systems.

4

Can CVE-2000-0331 be exploited remotely?

CVE-2000-0331 cannot be exploited remotely as it requires local access to the system.

5

What symptoms may indicate an issue related to CVE-2000-0331?

Symptoms of CVE-2000-0331 may include system crashes or unresponsive behavior when large environment variables are processed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203