Back

CVE-2001-0048

The "Configure Your Server" tool in Microsoft 2000 domain controllers installs a blank password for the Directory Service Restore Mode, which allows attackers with physical access to the controller to install malicious programs, aka the "Directory Service Restore Mode Password" vulnerability.

Published: Feb 12, 2001 Modified: Apr 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
microsoft windows_2000 *

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 0.37%

Top 41% most likely to be exploited

Threat Score 28.9 / 100

Data Sources

NVD EPSS