Windows NT 4.0 and Windows 2000 before URP1 for Windows...
Vulnerability Description
Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2005-2150
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.hsc.fr/ressources/presentations/null_sessions/
- http://marc.info/?l=bugtraq&m=112076409813099&w=2
- http://securitytracker.com/id?1014417
- http://www.securityfocus.com/bid/14177
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21286
- http://www.securityfocus.com/bid/14178
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21288
- http://secunia.com/advisories/14189
More from microsoft
View All →Affected Vendor
microsoft
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.