Vulnerabilities > CVE-2000-0979 - Unspecified vulnerability in Microsoft products

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
microsoft
exploit available

Summary

File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the "Share Level Password" vulnerability.

Vulnerable Configurations

Part Description Count
OS
Microsoft
4

Exploit-Db

  • descriptionMicrosoft Windows 9x / Me Share Level Password Bypass Vulnerability (1). CVE-2000-0979. Remote exploit for windows platform
    idEDB-ID:20283
    last seen2016-02-02
    modified2000-10-10
    published2000-10-10
    reporterstickler
    sourcehttps://www.exploit-db.com/download/20283/
    titleMicrosoft Windows 9x / Me Share Level Password Bypass Vulnerability 1
  • descriptionMicrosoft Windows 9x / Me Share Level Password Bypass Vulnerability (2). CVE-2000-0979. Remote exploit for windows platform
    idEDB-ID:20284
    last seen2016-02-02
    modified2000-10-10
    published2000-10-10
    reporterGabriel Maggiotti
    sourcehttps://www.exploit-db.com/download/20284/
    titleMicrosoft Windows 9x / Me Share Level Password Bypass Vulnerability 2

Oval

accepted2005-10-19T05:47:00.000-04:00
classvulnerability
contributors
  • nameTiffany Bergeron
    organizationThe MITRE Corporation
  • nameChristine Walzer
    organizationThe MITRE Corporation
descriptionFile and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the "Share Level Password" vulnerability.
familywindows
idoval:org.mitre.oval:def:996
statusaccepted
submitted2004-05-18T12:00:00.000-04:00
titleMicrosoft Share Level Password Vulnerability
version65