CVE-2001-1517

Windows 2000 - Cleartext Credential Exposure in RunAs Memory

Title source: llm
STIX 2.1

Description

RunAs (runas.exe) in Windows 2000 stores cleartext authentication information in memory, which could allow attackers to obtain usernames and passwords by executing a process that is allocated the same memory page after termination of a RunAs command. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it, and the original researcher did not respond to requests for additional information

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/3184
Patch, Vendor Advisory mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2001-q4/0041.html
Various Sources mailing-list x_refsource_bugtraq
http://cert.uni-stuttgart.de/archive/bugtraq/2001/11/msg00100.html

Scores

EPSS 0.0213
EPSS Percentile 80.2%

Details

Status published
Products (1)
microsoft/windows_2000 (3 CPE variants)
Published Dec 31, 2001
Tracked Since Feb 18, 2026