Running Windows 2000 LDAP Server over SSL, a function does not properly check the permissions of a user request when the directory principal is a domain user and the data attribute is the domain password, which allows local users to modify the login password of other users.
References
Configurations
Information
Published : 2001-07-20 21:00
Updated : 2018-10-12 14:30
NVD link : CVE-2001-0502
Mitre link : CVE-2001-0502
JSON object : View
CWE
Products Affected
microsoft
- windows_2000