Default User Account Vulnerability in Microsoft Site Server 3.0
CVE-2002-1769

Currently unrated

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
31 December 2002

Summary

Microsoft Site Server 3.0 versions prior to Service Pack 4 (SP4) implement a default user, named LDAP_Anonymous, which is secured by an easily guessable password, LdapPassword_1. This configuration enables remote attackers to gain unauthorized access by leveraging the 'Log on locally' privilege associated with this account, potentially allowing them to compromise the server and its data. Organizations using this version of Site Server should review their security settings and update to the latest service pack to mitigate this risk.

References

EPSS Score

28% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.