CVE-2001-0045 describes a critical vulnerability in Windows NT 4.0 where default permissions on the RAS Administration key allow local users to execute arbitrary commands. By modifying this key to point to a malicious DLL, an attacker can achieve full system compromise, including complete confidentiality, integrity, and availability loss. This vulnerability carries a CVSS score of 10.0, indicating maximum severity and ease of exploitation. While no public exploit code is readily available and it's not listed in CISA's KEV catalog, the vulnerability has garnered significant community discussion, suggesting awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_nt:4.0:*:*:*:*:*:*:* | ||
terminal_serverCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_nt:terminal_server:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.