CVE-2000-0487: Low severity Microsoft Windows 2000 vulnerability
The Protected Store in Windows 2000 does not properly select the strongest encryption when available, which causes it to use a default of 40-bit encryption instead of 56-bit DES encryption, aka the "Protected Store Key Length" vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure the Protected Store Key Length to use 56-bit DES encryption so it does not use the 40-bit default.
Microsoft Windows 2000 Protected Store Protected Store Key Length = 56-bit DES
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0487?
CVE-2000-0487 has a moderate severity rating due to the use of weaker encryption.
How do I fix CVE-2000-0487?
To fix CVE-2000-0487, ensure that the Windows 2000 system is updated with appropriate security patches from Microsoft.
What are the consequences of CVE-2000-0487?
The consequences of CVE-2000-0487 include potential exposure of sensitive data due to insufficient encryption strength.
Which versions of Windows are affected by CVE-2000-0487?
CVE-2000-0487 affects all versions of Microsoft Windows 2000.
Is it safe to use applications relying on the Protected Store in Windows 2000 with CVE-2000-0487?
It is not safe to use applications relying on the Protected Store in Windows 2000 without addressing CVE-2000-0487 due to weak encryption.