CVE-2001-1517
Windows 2000 - Cleartext Credential Exposure in RunAs Memory
Title source: llmDescription
RunAs (runas.exe) in Windows 2000 stores cleartext authentication information in memory, which could allow attackers to obtain usernames and passwords by executing a process that is allocated the same memory page after termination of a RunAs command. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it, and the original researcher did not respond to requests for additional information
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/3184
Patch, Vendor Advisory mailing-list
x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2001-q4/0041.html
Various Sources mailing-list
x_refsource_bugtraq
http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00100.html
Patch vdb-entry
x_refsource_xf
http://www.iss.net/security_center/static/7531.php
Scores
EPSS
0.0213
EPSS Percentile
80.2%
Details
Status
published
Products (1)
microsoft/windows_2000
(3 CPE variants)
Published
Dec 31, 2001
Tracked Since
Feb 18, 2026