CVE-2001-1302

Windows 2000 - Unauthenticated Account Enumeration via Password Change Error Messages

Title source: llm
STIX 2.1

Description

The change password option in the Windows Security interface for Windows 2000 allows attackers to use the option to attempt to change passwords of other users on other systems or identify valid accounts by monitoring error messages, possibly due to a problem in the NetuserChangePassword function.

References (3)

Core 3
Core References
Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3063
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/6876

Scores

EPSS 0.0151
EPSS Percentile 72.0%

Details

Status published
Products (1)
microsoft/windows_2000 (3 CPE variants)
Published Jul 18, 2001
Tracked Since Feb 18, 2026