First published: Wed Jul 18 2001(Updated: )
The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring error messages, possibly due to a problem in the NetuserChangePassword function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2000 | ||
Microsoft Windows 2000 | =sp2 | |
Microsoft Windows 2000 | =sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1302 is considered to have a medium severity due to its potential to allow unauthorized password changes and account identification.
Mitigation of CVE-2001-1302 involves applying the latest security patches from Microsoft and restricting access to the Windows Security interface.
CVE-2001-1302 primarily affects Microsoft Windows 2000 and its various service packs including SP1 and SP2.
Yes, CVE-2001-1302 can potentially be exploited by remote attackers to change passwords of other user accounts.
A temporary workaround for CVE-2001-1302 is to disable the change password feature for users who do not require it, while waiting for patches.