← Vulnerability feed

Vulnerability record · CVE-2001-0540 · published 30 October 2001

CVE-2001-0540: Windows Terminal Server RDP memory leak denial of service

Microsoft · Terminal Server

Terminal Services in Windows NT and Windows 2000 leaks memory when handling malformed Remote Desktop Protocol requests on port 3389. Repeated malformed requests exhaust server memory, degrading or halting the terminal service. The flaw is remotely reachable without authentication, making it a straightforward availability risk for exposed RDP endpoints.

5.0 CVSS 2.0 Medium EPSS 71% · top 0.6%
5.0CVSS 2.0 base score
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Memory leak in Terminal servers in Windows NT and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed Remote Desktop Protocol (RDP) requests to port 3389.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityRemote unauthenticated availability impact on legacy Windows Terminal Servers, with high EPSS but no KEV listing or confirmed public exploit, warrants medium priority.

What it is

Terminal Services in Windows NT and Windows 2000 leaks memory when handling malformed Remote Desktop Protocol requests on port 3389. Repeated malformed requests exhaust server memory, degrading or halting the terminal service. The flaw is remotely reachable without authentication, making it a straightforward availability risk for exposed RDP endpoints.

Impact

An unauthenticated remote attacker can exhaust memory on the Terminal Server, causing denial of service for legitimate RDP users and potentially destabilizing the host. No confidentiality or integrity impact is described; the effect is availability only.

Attack surface

Reached over the network via RDP on TCP port 3389; the CVSS vector AV:N/AC:L/Au:N confirms no authentication and no user interaction are required. Any host exposing Terminal Services to untrusted networks is in scope.

Exploitation

Not listed in CISA KEV and no reference tags indicate public exploit code, but EPSS is very high (0.71247, 99.4th percentile), suggesting elevated real-world likelihood of exploitation attempts. The record does not state whether working exploits are publicly available.

What to do

  • Apply the Microsoft security bulletin MS01-040 update for Terminal Services on affected Windows NT and Windows 2000 systems.
  • Restrict TCP 3389 exposure to trusted networks and block it at the perimeter where remote RDP is not required.
  • Place RDP behind a VPN or jump host so unauthenticated internet clients cannot reach the service.
  • Monitor Terminal Server memory usage and restart or isolate hosts showing unexplained exhaustion.
  • Retire or isolate end-of-life Windows NT and Windows 2000 Terminal Servers that cannot be patched.

Detection

  • Alert on sustained or repeated RDP connection attempts to port 3389 from single or many sources.
  • Track Terminal Server memory consumption trends and flag abnormal growth correlated with RDP session activity.
  • Review RDP connection logs for malformed or aborted handshakes and high-volume unauthenticated connection attempts.
  • Correlate host memory exhaustion events with concurrent inbound 3389 traffic to identify DoS attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2001-0540 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-4465Microsoft terminal server vulnerabilityMicrosoft Terminal Server, when running an application session with the "Start program at logon" and "Override settings from user profile and Client …EPSS 9.4%7.8CVE-2000-0305Beos vulnerabilityWindows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a l…EPSS 38%7.5CVE-2007-2593Microsoft terminal server vulnerabilityThe Terminal Server in Microsoft Windows 2003 Server, when using TLS, allows remote attackers to bypass SSL and self-signed certificate requirements,…EPSS 9.4%7.5CVE-1999-0909Microsoft terminal server permissions and access controls vulnerabilityMultihomed Windows systems allow a remote attacker to bypass IP source routing restrictions via a malformed packet with IP options, aka the "Spoofed …EPSS 12%7.5CVE-1999-0391Microsoft terminal server vulnerabilityThe cryptographic challenge of SMB authentication in Windows 95 and Windows 98 can be reused, allowing an attacker to replay the response and imperso…EPSS 4.9%7.2CVE-2000-0259Microsoft terminal server vulnerabilityThe default permissions for the Cryptography\Offload registry key used by the OffloadModExpo in Windows NT 4.0 allows local users to obtain compromis…EPSS 1.5%5.0CVE-2000-0404Microsoft terminal server vulnerabilityThe CIFS Computer Browser service allows remote attackers to cause a denial of service by sending a ResetBrowser frame to the Master Browser, aka the…EPSS 18%5.0CVE-2000-0331Microsoft terminal server vulnerabilityBuffer overflow in Microsoft command processor (CMD.EXE) for Windows NT and Windows 2000 allows a local user to cause a denial of service via a long …EPSS 7.5%

Source: NIST National Vulnerability Database (record CVE-2001-0540), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.