Skip to main content

CVE detail

CVE-2000-1139

The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability.

CVSS 7.5 · HighBuzz score 4.01 OTX pulses

Buzz score

Why this CVE is surfacing

Buzz score total 4.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 0.0 · diversity 0.0 · KEV 0.0 · OTX 4.0 · PoC 0.0
Mention score
0.0
0 evidence mentions in the snapshot
Diversity score
0.0
0 sources across 0 categories
KEV score
0.0
No KEV entry observed
OTX score
4.0
1 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
0 source links · newest first

    Exploit code

    Public exploit repository references

    Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

    0 repository references · best confidence N/A · max 0 stars
    No public PoC repositories have been matched yet.

    Related records

    Similar CVEs

    6 related CVEs with shared weakness or product evidence
    • CVE-2026-65313

      A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applie…

      CVSS 8.1 · High
    • CVE-2026-18452

      DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed API key to gain control over all…

      CVSS 10.0 · Critical
      2 mentions
    • CVE-2026-52539

      Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is…

      CVSS 9.1 · Critical
      2 mentions
    • CVE-2026-63239

      A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 buckets and SQS queues, exposing sensitive data and enabling mal…

      CVSS 5.4 · Medium
      1 mention
    • CVE-2026-13463

      IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files.

      CVSS 7.5 · High
      1 mention
    • CVE-2021-32087

      An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, which is…

      CVSS 8.8 · High
      2 mentions