CVE-2000-0420

CVSS 2.0 Score 7.2 of 10 (high)

Details

Published May 11, 2000
Updated: Nov 20, 2024

Summary

CVE-2000-0420 is a vulnerability affecting the default configuration of SYSKEY in Windows 2000. The issue lies in the fact that the startup key for SYSKEY is stored in the registry. An attacker who gains access to this information can recover it and subsequently use it to decrypt Encrypted File System (EFS) data, posing a significant security risk. This configuration weakness may allow unauthorized access to sensitive data. Organizations using Windows 2000 are advised to secure their SYSKEY startup keys to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 2000

Affected Vendors

  • Microsoft