CVE-2001-0349

Microsoft Windows 2000 - Command Injection

Title source: llm
STIX 2.1

Description

Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability.

References (4)

Core 4
Core References
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/587587
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/2849
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/6664

Scores

EPSS 0.0194
EPSS Percentile 78.2%

Details

Status published
Products (1)
microsoft/windows_2000
Published Jul 21, 2001
Tracked Since Feb 18, 2026