First published: Fri Jul 26 2002(Updated: )
Microsoft Windows 2000 running the Terminal Server 90-day trial version, and possibly other versions, does not apply group policies to incoming users when the number of connections to the SYSVOL share exceeds the maximum, e.g. with a maximum number of licenses, which can allow remote authenticated users to bypass group policies.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Terminal Services | =sp1 | |
Microsoft Windows Terminal Services | ||
Microsoft Windows Terminal Services | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0444 is regarded as a moderate severity vulnerability that can lead to unauthorized access to group policies.
To fix CVE-2002-0444, ensure that the number of connections to the SYSVOL share is below the maximum limit.
CVE-2002-0444 affects Microsoft Windows 2000 Terminal Services users, particularly those using the trial version.
The consequence of CVE-2002-0444 is that incoming users may not receive group policies, leading to inconsistent security settings.
While CVE-2002-0444 is an older vulnerability, systems running unpatched versions of Windows 2000 Terminal Services could still be at risk.