CNCVE编号:CNCVE-20010350 CVE编号:CAN-2001-0350 安全级别:中 漏洞中文描述: Microsoft Windows 2000 telnet 服务创建带有可预测名称的命名管道,并且不能适当确认它们,这就使得本地用户通过创建一个有可预测名称的命名管道并配以一个恶意程序,来执行任意命令。 漏洞英文描述: Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with this pipe。 漏洞参考: MS:MS01-031 URL:http://www.microsoft.com/technet/security/bulletin/MS01-031.asp 系统类型: Win2000/NT 漏洞类型:设计错误