CVE-2001-0048
The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.01%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password" vulnerability.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 2.01% probability · 80th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 2000
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/2133Exploit, Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-099
- http://www.securityfocus.com/bid/2133Exploit, Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-099
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.