CVE-2001-1122: Low severity Microsoft Windows NT vulnerability
Published Aug 3, 2001
·Updated
Windows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of service (crash in lsass.exe) by running the NT4ALL exploit program in 'SPECIAL' mode.
Affected Software
8 affected components
Microsoft Windows NT=4.0
Microsoft Windows NT=4.0-sp1
Microsoft Windows NT=4.0-sp2
Microsoft Windows NT=4.0-sp3
Microsoft Windows NT=4.0-sp4
Microsoft Windows NT=4.0-sp5
Microsoft Windows NT=4.0-sp6
Microsoft Windows NT=4.0-sp6a
Remediation
Patch Available
Event History
Aug 3, 2001
CVE Published
04:00 AM
Mar 15, 2002
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1122?
CVE-2001-1122 is classified as a denial of service vulnerability affecting Windows NT 4.0 SP 6a.
2
How do I fix CVE-2001-1122?
To fix CVE-2001-1122, it is recommended to apply the latest service pack or updates to Windows NT 4.0.
3
Who is affected by CVE-2001-1122?
CVE-2001-1122 affects local users who have write access to the winnt/system32 directory on Windows NT 4.0.
4
What exploit is associated with CVE-2001-1122?
CVE-2001-1122 is associated with the NT4ALL exploit program which can crash lsass.exe.
5
Can remote users exploit CVE-2001-1122?
No, CVE-2001-1122 can only be exploited by local users with specific system access rights.