Oval Definition:oval:org.mitre.oval:def:1455
Revision Date:2008-03-24Version:46
Title:Windows NT Certificate Validation Identity Spoofing Vulnerability (Test 1)
Description:Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862).
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2002-1183
Platform(s):Microsoft Windows NT
Product(s):Certificate Validation
Definition Synopsis
  • Windows NT Server 4.0 is installed
  • Microsoft Windows NT is installed
  • AND Windows NT server product option
  • this is an NT Server (stand-alone)
  • OR this is an NT Server (domain controller)
  • AND the version of cryptdlg.dll is less then 5.0.1558.6072
  • AND NOT the patch Q329115 is installed
  • AND NOT the patch kb835732 is installed
  • BACK