Vulnerability Description
The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password" vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 2000 | All versions |
References
- http://www.securityfocus.com/bid/2133ExploitPatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-09
- http://www.securityfocus.com/bid/2133ExploitPatchVendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2000/ms00-09
FAQ
What is CVE-2001-0048?
CVE-2001-0048 is a vulnerability with a CVSS score of 7.2 (HIGH). The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to...
How severe is CVE-2001-0048?
CVE-2001-0048 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-0048?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows 2000.