Vulnerability Name:

CCN-11378

Published:2003-02-19
Updated:2003-02-19
Summary:Multiple operating systems could allow a local attacker with physical access to the computer to gain unauthorized access to the file system. The attacker could boot the system using a boot disk for an operating system that has a different version number than the operating system that is currently running on the computer, and possibly gain complete administrative access to the system. On Windows XP systems, this can be accomplished by using a Windows 2000 boot disk to launch the Windows XP Recovery Console.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Consequences:Bypass Security
References:Source: CCN
Type: NTBugTraq Mailing List, Wed, 19 Feb 2003 13:50:15 -0800
Article: Windows XP Wide Open Using Windows 2000 CD-ROM

Source: CCN
Type: NTBugTraq Mailing List, Thu, 20 Feb 2003 08:25:48 -0600
Re: Article: Windows XP Wide Open Using Windows 2000 CD-ROM

Source: CCN
Type: NTBugTraq Mailing List, Thu, 20 Feb 2003 08:39:51 -0600
Re: Article: Windows XP Wide Open Using Windows 2000 CD-ROM

Source: CCN
Type: NTBugTraq Mailing List, Thu, 20 Feb 2003 15:19:38 +0000
Re: Article: Windows XP Wide Open Using Windows 2000 CD-ROM

Source: CCN
Type: NTBugTraq Mailing List, Thu, 20 Feb 2003 16:31:29 +0100
Re: Article: Windows XP Wide Open Using Windows 2000 CD-ROM

Source: CCN
Type: Wired News 02:00 AM Feb. 20, 2003 PT
XP Hole Plagues All Similar Apps

Source: XF
Type: UNKNOWN
boot-disk-unauth-access(11378)

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/o:linux:kernel:*:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows:*:*:*:*:*:*:*:*
  • OR cpe:/o:unix:unix:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    linux kernel *
    microsoft windows *
    unix unix *