Vulnerability Description
Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could allow local users to install Trojan horses that cannot be stopped with the Task Manager.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 2000 | All versions |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/archive/1/197195Broken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/3033Broken LinkPatchThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6919Third Party AdvisoryVDB Entry
- http://www.securityfocus.com/archive/1/197195Broken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/3033Broken LinkPatchThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6919Third Party AdvisoryVDB Entry
FAQ
What is CVE-2001-1238?
CVE-2001-1238 is a vulnerability with a CVSS score of 7.8 (HIGH). Task Manager in Windows 2000 does not allow local users to end processes with uppercase letters named (1) winlogon.exe, (2) csrss.exe, (3) smss.exe and (4) services.exe via the Process tab which could...
How severe is CVE-2001-1238?
CVE-2001-1238 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-1238?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows 2000.