CVE-2001-0350

Microsoft Windows 2000 - Command Injection

Title source: llm
STIX 2.1

Description

Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/6664

Scores

EPSS 0.0148
EPSS Percentile 71.5%

Details

Status published
Products (1)
microsoft/windows_2000
Published Jul 21, 2001
Tracked Since Feb 18, 2026