Microsoft Windows 2000目录服务储存模式空白密码漏洞

漏洞信息详情

Microsoft Windows 2000目录服务储存模式空白密码漏洞

漏洞简介

Microsoft 2000域控制器\”Configure Your Server\”工具安装Directory Service Restore Mode空白密码。物理访问控制器的攻击者可以利用该漏洞安装恶意程序,也称为\”Directory Service Restore Mode Password\”漏洞。

漏洞公告

Microsoft has released patches which will eliminate this vulnerability. The patch also includes the SETPWD tool which allows the administrator to modify the value of the Directory Service Restore Mode and Recovery Console password. The command syntax for the tool is:
SETPWD [/s:servername]
Microsoft Windows 2000 Advanced Server

Microsoft Windows 2000 Server

参考网址

来源: BID
名称: 2133
链接:http://www.securityfocus.com/bid/2133

来源: MS
名称: MS00-099
链接:http://www.microsoft.com/technet/security/bulletin/MS00-099.asp

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享