CVE-2001-1519: Low severity microsoft windows 2000 vulnerability
DISPUTED RunAs (runas.exe) in Windows 2000 allows local users to create a spoofed named pipe when the service is stopped, then capture cleartext usernames and passwords when clients connect to the service. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1519?
CVE-2001-1519 is considered a moderate severity vulnerability as it allows local users to capture cleartext usernames and passwords.
How do I fix CVE-2001-1519?
To mitigate CVE-2001-1519, ensure that administrative privileges are appropriately managed and consider disabling the RunAs functionality if not necessary.
Who is affected by CVE-2001-1519?
CVE-2001-1519 affects local users on systems running Microsoft Windows 2000.
What does CVE-2001-1519 involve?
CVE-2001-1519 involves the ability for local users to create a spoofed named pipe, potentially capturing sensitive information.
Is CVE-2001-1519 still a concern?
While CVE-2001-1519 is largely historical due to the end of support for Windows 2000, it highlights important lessons in privilege management.