CVE-2000-1164: Critical severity Att WinVNC vulnerability
Published Jan 9, 2001
·Updated
WinVNC installs the WinVNC3 registry key with permissions that give Special Access (read and modify) to the Everybody group, which allows users to read and modify sensitive information such as passwords and gain access to the system.
Affected Software
2 affected components
Att WinVNC=3.3.3
Att WinVNC=3.3.3r7
Remediation
Patch Available
Event History
Jan 9, 2001
CVE Published
05:00 AM
May 7, 2001
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-1164?
The severity of CVE-2000-1164 is classified as high due to its potential to expose sensitive information.
2
How do I fix CVE-2000-1164?
To fix CVE-2000-1164, change the permissions of the WinVNC3 registry key to restrict access from the Everybody group.
3
What systems are affected by CVE-2000-1164?
CVE-2000-1164 affects AT&T WinVNC versions 3.3.3 and 3.3.3r7.
4
What type of information could be accessed due to CVE-2000-1164?
Due to CVE-2000-1164, sensitive information such as user passwords could be accessed and modified.
5
Who can exploit CVE-2000-1164?
Any user with local access to the system can exploit CVE-2000-1164 to read or modify sensitive registry information.