CVE-2001-0373
2.1 · LOWOverview
CVE-2001-0373 is a low-severity vulnerability affecting microsoft windows_2000. It was published on June 18, 2001 and has a CVSS 2.0 base score of 2.1 (LOW).
This vulnerability has a CVSS 2.0 base score of 2.1, rated LOW. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.
Technical Description
The default configuration of the Dr. Watson program in Windows NT and Windows 2000 generates user.dmp crash dump files with world-readable permissions, which could allow a local user to gain access to sensitive information.
Remediation
Check the references section for vendor advisories and patches from microsoft. Update windows_2000 to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
Affected Products
| Vendor | Product | Versions | Status |
|---|
References
Frequently Asked Questions
What is CVE-2001-0373?
CVE-2001-0373 is a low-severity vulnerability affecting microsoft windows_2000. It was published on June 18, 2001 and has a CVSS 2.0 base score of 2.1 (LOW).
How severe is CVE-2001-0373?
This vulnerability has a CVSS 2.0 base score of 2.1, rated LOW. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.
How do I fix or remediate CVE-2001-0373?
Check the references section for vendor advisories and patches from microsoft. Update windows_2000 to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
How can CyberStrike help with CVE-2001-0373?
CyberStrike's AI-powered security agents can automatically detect CVE-2001-0373 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.
How CyberStrike Helps
AI agents map your attack surface to find vulnerabilities like this one.
Automated penetration testing that runs continuously, not just quarterly.
AI-driven PR review catches vulnerable dependencies before they ship.
Browser-based exploitation validates findings with real proof-of-concept.
Related LOW CVEs from 2001
View all →crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure
ghostscript before 5.10-16 allows local users to overwrite files of other users via a symlink attack
Race condition in ptrace in Linux kernel 2.4 and 2.2 allows local users to gain privileges by using
Sendmail before 8.11.4, and 8.12.0 before 8.12.0.Beta10, allows local users to cause a denial of ser
Lmail 2.7 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temp
vi as included with SCO OpenServer 5.0 - 5.0.6 allows a local attacker to overwrite arbitrary files
registrar in the HP resource monitor service allows local users to read and modify arbitrary files b
StarOffice 5.2 follows symlinks and sets world-readable permissions for the /tmp/soffice.tmp directo
Unknown vulnerability in sockfilter for Linux kernel before 2.2.19 related to "boundary cases," with
Unknown vulnerabilities in strnlen_user for Linux kernel before 2.2.19, with unknown impact.
ssh-keygen in ssh 1.2.27 - 1.2.30 with Secure-RPC can allow local attackers to recover a SUN-DES-1 m
Vulnerability in exuberant-ctags before 3.2.4-0.1 insecurely creates temporary files.