Vulnerabilities > CVE-2001-1518 - Denial of Services vulnerability in Microsoft Windows 2000 RunAs Service

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
local
low complexity
microsoft
exploit available

Summary

RunAs (runas.exe) in Windows 2000 only creates one session instance at a time, which allows local users to cause a denial of service (RunAs hang) by creating a named pipe session with the authentication server without any request for service. NOTE: the vendor disputes this vulnerability, however the vendor also presents a scenario in which other users could be affected if running on a Terminal Server. Therefore this is a vulnerability.

Vulnerable Configurations

Part Description Count
OS
Microsoft
3

Exploit-Db

descriptionMicrosoft Windows 2000 RunAs Service Denial of Services Vulnerability. CVE-2001-1518. Dos exploit for windows platform
idEDB-ID:21099
last seen2016-02-02
modified2001-12-11
published2001-12-11
reporterCamisade
sourcehttps://www.exploit-db.com/download/21099/
titleMicrosoft Windows 2000 RunAs Service Denial of Services Vulnerability