Microsoft Windows 2000 LDAP SSL Password Modification Vulnerability
BID:2929
Info
Microsoft Windows 2000 LDAP SSL Password Modification Vulnerability
| Bugtraq ID: | 2929 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 25 2001 12:00AM |
| Updated: | Jun 25 2001 12:00AM |
| Credit: | Discovered by Jon McDonald and published in a Microsoft Security Bulletin MS01-036 on June 25, 2001. |
| Vulnerable: |
Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows 2000 LDAP SSL Password Modification Vulnerability
Due to inproper permissions verification when submitting a password modify request, a normal user can successfully change any user's Windows 2000 domain login password. This is accomplished if LDAP requests are being made over a SSL session.
Due to inproper permissions verification when submitting a password modify request, a normal user can successfully change any user's Windows 2000 domain login password. This is accomplished if LDAP requests are being made over a SSL session.
References
Microsoft Windows 2000 LDAP SSL Password Modification Vulnerability
References:
References:
- McDonald finds Security Flaw in Windows 2000 (Entrigue Systems)
- Microsoft Security Bulletin MS01-036 (Microsoft)
- Microsoft Security Bulletin MS02-016 (Microsoft)