Vulnerability Name:

CVE-2002-0421 (CCN-8388)

Assigned:2002-03-06
Published:2002-03-06
Updated:2008-09-05
Summary:IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr password changing programs in the /iisadmpwd directory, including (1) aexp2.htr, (2) aexp2b.htr, (3) aexp3.htr , or (4) aexp4.htr.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Bypass Security
References:Source: CCN
Type: BugTraq Mailing List, Wed Mar 06 2002 - 03:07:05 CST
NT user (who is locked changing his/her password by administrator ) can bypass the security policy and Change the password.

Source: MITRE
Type: CNA
CVE-2002-0421

Source: BUGTRAQ
Type: Vendor Advisory
20020306 NT user (who is locked changing his/her password by administrator ) can bypass the security policy and Change the password.

Source: XF
Type: Patch, Vendor Advisory
winnt-pw-policy-bypass(8388)

Source: CCN
Type: OSVDB ID: 13427
Microsoft IIS aexp2.htr Password Policy Bypass

Source: CCN
Type: OSVDB ID: 13428
Microsoft IIS aexp2b.htr Password Policy Bypass

Source: CCN
Type: OSVDB ID: 13429
Microsoft IIS aexp3.htr Password Policy Bypass

Source: CCN
Type: OSVDB ID: 13430
Microsoft IIS aexp4.htr Password Policy Bypass

Source: BID
Type: Patch, Vendor Advisory
4236

Source: CCN
Type: BID-4236
Microsoft Windows NT Security Policy Bypass Vulnerability

Source: XF
Type: UNKNOWN
winnt-pw-policy-bypass(8388)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:microsoft:windows_nt:4.0:*:server:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_nt:4.0:sp1:*:*:server:*:x86:*
  • OR cpe:/o:microsoft:windows_nt:4.0:sp2:*:*:server:*:x86:*
  • OR cpe:/o:microsoft:windows_nt:4.0:sp3:*:*:server:*:x86:*
  • OR cpe:/o:microsoft:windows_nt:4.0:sp4:*:*:server:*:x86:*
  • OR cpe:/o:microsoft:windows_nt:4.0:sp5:*:*:server:*:x86:*
  • OR cpe:/o:microsoft:windows_nt:4.0:sp6:*:*:server:*:x86:*
  • OR cpe:/o:microsoft:windows_nt:4.0:sp6a:*:*:server:*:x86:*

  • Configuration CCN 1:
  • cpe:/o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_information_services:4.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    microsoft windows nt 4.0
    microsoft windows nt 4.0 sp1
    microsoft windows nt 4.0 sp2
    microsoft windows nt 4.0 sp3
    microsoft windows nt 4.0 sp4
    microsoft windows nt 4.0 sp5
    microsoft windows nt 4.0 sp6
    microsoft windows nt 4.0 sp6a
    microsoft windows nt 4.0
    microsoft internet information server 4.0