CVE-2001-1517: Low severity microsoft windows 2000 vulnerability
DISPUTED RunAs (runas.exe) in Windows 2000 stores cleartext authentication information in memory, which could allow attackers to obtain usernames and passwords by executing a process that is allocated the same memory page after termination of a RunAs command. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it, and the original researcher did not respond to requests for additional information.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1517?
CVE-2001-1517 is considered a moderate vulnerability due to the potential exposure of sensitive authentication information.
How do I fix CVE-2001-1517?
To address CVE-2001-1517, it is recommended to apply the latest security patches for Windows 2000 or upgrade to a supported version of Windows.
What systems are affected by CVE-2001-1517?
CVE-2001-1517 affects Microsoft Windows 2000, including Service Pack 1 and Service Pack 2.
What is the main risk associated with CVE-2001-1517?
The main risk of CVE-2001-1517 is that attackers could potentially recover usernames and passwords stored in cleartext in memory.
Is CVE-2001-1517 still relevant today?
While CVE-2001-1517 is an older vulnerability, it is relevant for environments still using Windows 2000, which may be at risk if not properly secured.