Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability.
Link | Tags |
---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-031 | vendor advisory |
http://www.kb.cert.org/vuls/id/587587 | third party advisory us government resource |
http://www.securityfocus.com/bid/2849 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/6664 | vdb entry |