Back

CVE-2000-1139

The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability.

Published: Jan 9, 2001 Modified: Apr 16, 2026
CWE-798

CVSS Metrics

Affected Products (1)

Vendor Product Version
microsoft exchange_server 2000

GitHub Security Advisory GHSA-2r9p-58g6-hvj9

The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 6.26%

Top 9% most likely to be exploited

Threat Score 31.9 / 100

Data Sources

NVD EPSS GitHub