Vulnerability record · CVE-2001-0540 · published 30 October 2001
CVE-2001-0540: Windows Terminal Server RDP memory leak denial of service
Microsoft · Terminal Server
Terminal Services in Windows NT and Windows 2000 leaks memory when handling malformed Remote Desktop Protocol requests on port 3389. Repeated malformed requests exhaust server memory, degrading or halting the terminal service. The flaw is remotely reachable without authentication, making it a straightforward availability risk for exposed RDP endpoints.
Description
Memory leak in Terminal servers in Windows NT and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed Remote Desktop Protocol (RDP) requests to port 3389.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityRemote unauthenticated availability impact on legacy Windows Terminal Servers, with high EPSS but no KEV listing or confirmed public exploit, warrants medium priority.
What it is
Terminal Services in Windows NT and Windows 2000 leaks memory when handling malformed Remote Desktop Protocol requests on port 3389. Repeated malformed requests exhaust server memory, degrading or halting the terminal service. The flaw is remotely reachable without authentication, making it a straightforward availability risk for exposed RDP endpoints.
Impact
An unauthenticated remote attacker can exhaust memory on the Terminal Server, causing denial of service for legitimate RDP users and potentially destabilizing the host. No confidentiality or integrity impact is described; the effect is availability only.
Attack surface
Reached over the network via RDP on TCP port 3389; the CVSS vector AV:N/AC:L/Au:N confirms no authentication and no user interaction are required. Any host exposing Terminal Services to untrusted networks is in scope.
Exploitation
Not listed in CISA KEV and no reference tags indicate public exploit code, but EPSS is very high (0.71247, 99.4th percentile), suggesting elevated real-world likelihood of exploitation attempts. The record does not state whether working exploits are publicly available.
What to do
- Apply the Microsoft security bulletin MS01-040 update for Terminal Services on affected Windows NT and Windows 2000 systems.
- Restrict TCP 3389 exposure to trusted networks and block it at the perimeter where remote RDP is not required.
- Place RDP behind a VPN or jump host so unauthenticated internet clients cannot reach the service.
- Monitor Terminal Server memory usage and restart or isolate hosts showing unexplained exhaustion.
- Retire or isolate end-of-life Windows NT and Windows 2000 Terminal Servers that cannot be patched.
Detection
- Alert on sustained or repeated RDP connection attempts to port 3389 from single or many sources.
- Track Terminal Server memory consumption trends and flag abnormal growth correlated with RDP session activity.
- Review RDP connection logs for malformed or aborted handshakes and high-volume unauthenticated connection attempts.
- Correlate host memory exhaustion events with concurrent inbound 3389 traffic to identify DoS attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2001-0540 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2001-0540), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.