Oval Definition:oval:org.mitre.oval:def:1059
Revision Date:2008-03-24Version:46
Title:Microsoft Certificate Validation Flaw Identity Spoofing Vulnerability (Variant)
Description:Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862).
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2002-1183
Platform(s):Microsoft Windows NT
Product(s):Certificate Validation
Definition Synopsis
  • Windows NT Server 4.0, Terminal Server Edition is installed
  • Microsoft Windows NT is installed
  • AND this is an NT Terminal Server
  • AND the version of cryptdlg.dll is less then 5.0.1558.6072
  • AND NOT the patch Q329115 is installed
  • AND NOT the patch kb835732 is installed
  • BACK