First published: Mon Dec 31 2001(Updated: )
** DISPUTED ** RunAs (runas.exe) in Windows 2000 stores cleartext authentication information in memory, which could allow attackers to obtain usernames and passwords by executing a process that is allocated the same memory page after termination of a RunAs command. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it, and the original researcher did not respond to requests for additional information.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2000 | ||
Microsoft Windows 2000 | =sp2 | |
Microsoft Windows 2000 | =sp1 | |
=sp1 | ||
=sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1517 is considered a moderate vulnerability due to the potential exposure of sensitive authentication information.
To address CVE-2001-1517, it is recommended to apply the latest security patches for Windows 2000 or upgrade to a supported version of Windows.
CVE-2001-1517 affects Microsoft Windows 2000, including Service Pack 1 and Service Pack 2.
The main risk of CVE-2001-1517 is that attackers could potentially recover usernames and passwords stored in cleartext in memory.
While CVE-2001-1517 is an older vulnerability, it is relevant for environments still using Windows 2000, which may be at risk if not properly secured.