SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2000-0197

The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the local user to gain privileges by providing a Trojan horse batch file in place of the original batch file.

MEDIUM 4.6EPSS 1.64%

Does this matter?

Lower severity and a low EPSS score (1.64%). Track it; it rarely justifies an emergency change on its own.

Description

The Windows NT scheduler uses the drive mapping of the interactive user who is currently logged onto the system, which allows the local user to gain privileges by providing a Trojan horse batch file in place of the original batch file.

CVSS 2.0
4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS
1.64% probability · 75th percentile
CISA KEV
Not listed
Affected
microsoft/windows nt
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.