积极预防 及时发现
快速响应 力保恢复
在安全套接层(SSL)上运行Windows 2000 轻型目录协议(LDAP)时,当目录负责人(di...
发布时间:2001-07-21 信息来源:管理员

CNCVE编号:CNCVE-20010502 CVE编号:CAN-2001-0502 安全级别:中 漏洞中文描述: 在安全套接层(SSL)上运行Windows 2000 轻型目录协议(LDAP)时,当目录负责人(directory principal)是一个域用户并且数据属性是域口令时,一个函数将不能正确检查某个用户请求的权限,这使得本地用户可以修改其它用户的登陆口令。 漏洞英文描述: Running Windows 2000 LDAP Server over SSL, a function does not properly check the permissions of a user request when the directory principal is a domain user and the data attribute is the domain password, which allows local users to modify the login password. 漏洞参考: MS:MS01-036 URL:http://www.microsoft.com/technet/security/bulletin/MS01-036.asp 系统类型: Win2000/NT 漏洞类型:权限有效性检查错误