LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2001-1517

CVE-2001-1517

CVSS 2.1 · LOW

Summary

RunAs (runas.exe) in Windows 2000 stores cleartext authentication information in memory, which could allow attackers to obtain usernames and passwords by executing a process that is allocated the same memory page after termination of a RunAs command. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it, and the original researcher did not respond to requests for additional information

CVSS 2.0 breakdown

Base score2.1 (LOW)
VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Attack vectorLOCAL
Attack complexityLOW
ConfidentialityPARTIAL
IntegrityNONE
AvailabilityNONE

Affected products

Microsoft windows 2000
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD. NVD last modified 2026-04-16. Always verify against the vendor advisory before acting.

Scroll to Top