CVE-2005-2150
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
11/07/2005
Last modified:
03/04/2025
Description
Windows NT 4.0 and Windows 2000 before URP1 for Windows 2000 SP4 does not properly prevent NULL sessions from accessing certain alternate named pipes, which allows remote attackers to (1) list Windows services via svcctl or (2) read eventlogs via eventlog.
Impact
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:* | ||
cpe:2.3:o:microsoft:windows_nt:4.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://marc.info/?l=bugtraq&m=112076409813099&w=2
- http://secunia.com/advisories/14189
- http://securitytracker.com/id?1014417=
- http://www.hsc.fr/ressources/presentations/null_sessions/
- http://www.securityfocus.com/bid/14177
- http://www.securityfocus.com/bid/14178
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21286
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21288
- http://marc.info/?l=bugtraq&m=112076409813099&w=2
- http://secunia.com/advisories/14189
- http://securitytracker.com/id?1014417=
- http://www.hsc.fr/ressources/presentations/null_sessions/
- http://www.securityfocus.com/bid/14177
- http://www.securityfocus.com/bid/14178
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21286
- https://exchange.xforce.ibmcloud.com/vulnerabilities/21288