What is the vulnerability?
The Windows NT 4.0 and Windows 2000 command processor (CMD.EXE) does not correctly constrain the length of environment strings that it receives. If CMD.EXE received an excessively-long environment string, it would crash. Under certain conditions, this could cause the memory allocated to the process to become temporarily unavailable.