CVE

Id
4317  
CVE No.
CVE-2001-1517  
Status
Candidate  
Description
** DISPUTED ** RunAs (runas.exe) in Windows 2000 stores cleartext authentication information in memory, which could allow attackers to obtain usernames and passwords by executing a process that is allocated the same memory page after termination of a RunAs command. NOTE: the vendor disputes this issue, saying that administrative privileges are already required to exploit it, and the original researcher did not respond to requests for additional information.  
Phase
Assigned (20050714)  
Votes
None (candidate not yet proposed)  
Comments