Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the second of two variants of this vulnerability.
Link | Tags |
---|---|
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-031 | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/6664 | vdb entry |