Back
CVE-2001-0349
Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with it, the first of two variants of this vulnerability.
Published: Jul 21, 2001
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| microsoft | windows_2000 | * |
GitHub Security Advisory GHSA-5gfm-vq6m-rxf2
Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not...
References (8)
- http://www.kb.cert.org/vuls/id/587587 US Government Resource
- http://www.securityfocus.com/bid/2849
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-031
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6664
- http://www.kb.cert.org/vuls/id/587587 US Government Resource
- http://www.securityfocus.com/bid/2849
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-031
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6664
Risk Scores
CVSS Score
7.2 / 10
EPSS Score
1.94%
Top 22% most likely to be exploited
Threat Score
29.4 / 100
Data Sources
NVD
EPSS
GitHub