First published: Thu Oct 06 2005(Updated: )
The SECEDIT command on Microsoft Windows 2000 before Update Rollup 1 for SP4, when using a security template to set Access Control Lists (ACLs) on folders, does not apply ACLs on folders that are listed after a long folder entry, which could result in less secure permissions than specified by the template.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2000 | =sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3168 is classified as a medium severity vulnerability due to its potential to allow less secure permissions on folders.
To fix CVE-2005-3168, you should apply Update Rollup 1 for SP4 for Microsoft Windows 2000.
CVE-2005-3168 affects Microsoft Windows 2000 running Service Pack 4 prior to Update Rollup 1.
The consequence of CVE-2005-3168 is that it could result in improperly applied Access Control Lists on certain folders, leading to inadequate security.
CVE-2005-3168 is less relevant today as Microsoft Windows 2000 is no longer supported, but awareness of historical vulnerabilities is important for legacy systems.