CVE-2001-1302: Low severity Microsoft Windows 2000 vulnerability
The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring error messages, possibly due to a problem in the NetuserChangePassword function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1302?
CVE-2001-1302 is considered to have a medium severity due to its potential to allow unauthorized password changes and account identification.
How can I mitigate CVE-2001-1302?
Mitigation of CVE-2001-1302 involves applying the latest security patches from Microsoft and restricting access to the Windows Security interface.
What are the affected systems for CVE-2001-1302?
CVE-2001-1302 primarily affects Microsoft Windows 2000 and its various service packs including SP1 and SP2.
Can CVE-2001-1302 allow remote attacks?
Yes, CVE-2001-1302 can potentially be exploited by remote attackers to change passwords of other user accounts.
Is there a workaround for CVE-2001-1302?
A temporary workaround for CVE-2001-1302 is to disable the change password feature for users who do not require it, while waiting for patches.