CVE-2001-0003
Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password,…
Does this matter?
Lower severity and a low EPSS score (7.37%). Track it; it rarely justifies an emergency change on its own.
Description
Web Extender Client (WEC) in Microsoft Office 2000, Windows 2000, and Windows Me does not properly process Internet Explorer security settings for NTLM authentication, which allows attackers to obtain NTLM credentials and possibly obtain the password, aka the "Web Client NTLM Authentication" vulnerability.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 7.37% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/office · microsoft/windows 2000 · microsoft/windows me · microsoft/windows nt
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/2199Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-001
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5920
- http://www.securityfocus.com/bid/2199Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-001
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5920
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.