Default User Account Vulnerability in Microsoft Site Server 3.0
CVE-2002-1769
Currently unrated
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 31 December 2002
Summary
Microsoft Site Server 3.0 versions prior to Service Pack 4 (SP4) implement a default user, named LDAP_Anonymous, which is secured by an easily guessable password, LdapPassword_1. This configuration enables remote attackers to gain unauthorized access by leveraging the 'Log on locally' privilege associated with this account, potentially allowing them to compromise the server and its data. Organizations using this version of Site Server should review their security settings and update to the latest service pack to mitigate this risk.
References
EPSS Score
28% chance of being exploited in the next 30 days.
Timeline
Vulnerability Reserved
Vulnerability published