CVE-2004-0540: Critical severity Microsoft Windows 2000 vulnerability
Microsoft Windows 2000, when running in a domain whose Fully Qualified Domain Name (FQDN) is exactly 8 characters long, does not prevent users with expired passwords from logging on to the domain.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0540?
The severity of CVE-2004-0540 is considered to be moderate as it allows users with expired passwords to log onto the domain.
What are the impacts of CVE-2004-0540 on a Windows 2000 system?
The impact of CVE-2004-0540 includes unauthorized access to the system by users with expired passwords within domains with an FQDN of exactly 8 characters.
How do I fix CVE-2004-0540?
To fix CVE-2004-0540, administrators should implement password policies that prevent users with expired passwords from logging in.
Who is affected by CVE-2004-0540?
Users operating in a Microsoft Windows 2000 domain with an FQDN exactly 8 characters long are affected by CVE-2004-0540.
What versions of Windows are vulnerable to CVE-2004-0540?
CVE-2004-0540 specifically affects Microsoft Windows 2000 running in certain domain configurations.