CNCVE编号:CNCVE-20010349 CVE编号:CAN-2001-0349 安全级别:高 漏洞中文描述: Microsoft Windows 2000 telnet服务用可以预测的名字创建命名管道并且不能正确的校验它们,这将导致本地用户可以使用可预测名来创建一个命名管道并且用这个管道和恶意的程序相连从而可以执行任意命令。 漏洞英文描述: Microsoft Windows 2000 telnet service creates named pipes with predictable names and does not properly verify them, which allows local users to execute arbitrary commands by creating a named pipe with the predictable name and associating a malicious program with this pipe。 漏洞参考: MS:MS01-031 URL:http://www.microsoft.com/technet/security/bulletin/MS01-031.asp 系统类型: Win2000/NT 漏洞类型:设计错误