CVE-2001-0048 describes a critical vulnerability in Microsoft Windows 2000 domain controllers, where the "Configure Your Server" tool sets a blank password for Directory Service Restore Mode. This allows an attacker with physical access to the controller to install malicious programs, leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation is reported, the vulnerability has a high CVSS score of 7.2 and significant community discussion, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.