CVE-2001-1302
Windows 2000 - Unauthenticated Account Enumeration via Password Change Error Messages
Title source: llmDescription
The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring error messages, possibly due to a problem in the NetuserChangePassword function.
References (3)
Core 3
Core References
Various Sources mailing-list
x_refsource_ntbugtraq
http://www.ntbugtraq.com/default.asp?pid=36&sid=1&A2=ind0107&L=ntbugtraq&F=P&S=&P=1911
Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/3063
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/6876
Scores
EPSS
0.0151
EPSS Percentile
72.0%
Details
Status
published
Products (1)
microsoft/windows_2000
(3 CPE variants)
Published
Jul 18, 2001
Tracked Since
Feb 18, 2026