Customer Security Bulletin (CSB01-09) : Microsoft (MS01-036): Using Microsoft Windows 2000 LDAP over SSL Could Enable Passwords to Be Changed
A function exposed in Microsoft Windows 2000 via LDAP could enable passwords to be changed if the LDAP server has been configured to support LDAP over SSL sessions. Here's what to do:
Customer Security Bulletin (CSB01-09)