CVE-2000-0834
The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to the malicious server, aka the "Windows 2000 Telnet…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 39.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to the malicious server, aka the "Windows 2000 Telnet Client NTLM Authentication" vulnerability.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 39.61% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 2000
- Source
- cve@mitre.org
References
- http://www.atstake.com/research/advisories/2000/a091400-1.txt
- http://www.securityfocus.com/bid/1683Exploit, Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-067
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5242
- http://www.atstake.com/research/advisories/2000/a091400-1.txt
- http://www.securityfocus.com/bid/1683Exploit, Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-067
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5242
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.