First published: Mon Jul 11 2005(Updated: )
Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows NT | =4.0 | |
Microsoft Windows 2000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2150 is considered a high severity vulnerability due to its potential for unauthorized access to sensitive system information.
To remediate CVE-2005-2150, apply the latest security patches available for Windows 2000 SP4 and Windows NT 4.0.
CVE-2005-2150 affects Windows NT 4.0 and Windows 2000 operating systems prior to URP1 for Windows 2000 SP4.
The vulnerability can allow remote attackers to list Windows services or read event logs, which can aid in further exploitation.
While CVE-2005-2150 is old, it remains a concern for legacy systems still in use, which can expose organizations to security risks.