Oval Definition:oval:org.mitre.oval:def:930
Revision Date:2005-02-16Version:42
Title:Windows 2000 IIS Out of Process Privilege Elevation Vulnerability
Description:Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2002-0869
Platform(s):Microsoft Windows 2000
Product(s):Microsoft Internet Information Server (IIS)
Definition Synopsis
  • IIS major version equals 5
  • AND IIS minor version equals 0
  • AND File %windir%\System32\msw3prt.dll is less than 5.0.2195.5807
  • AND NOT Patch Q327696 Installed
  • AND NOT Patch Q811114 Installed
  • BACK