Vulnerability Name:

CVE-2002-0620 (CCN-9423)

Assigned:2002-06-26
Published:2002-06-26
Updated:2018-10-12
Summary:Buffer overflow in the Profile Service of Microsoft Commerce Server 2000 allows remote attackers to cause the server to fail or run arbitrary code in the LocalSystem security context via an input field using an affected API.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: CCN
Type: NGSSoftware Insight Security Research Advisory #NISR03062002
Remotely Exploitable Buffer Overruns in Microsoft's Commerce Server 2000/2

Source: MITRE
Type: CNA
CVE-2002-0620

Source: CCN
Type: Microsoft Security Bulletin MS02-033
Unchecked Buffer in Profile Service Could Allow Code Execution in Commerce Server (Q322273)

Source: CCN
Type: OSVDB ID: 14430
Microsoft Commerce Server 2000 Profile Service Affected API Overflow

Source: BID
Type: UNKNOWN
4853

Source: CCN
Type: BID-4853
Microsoft Commerce Server 2000 Profile Service Buffer Overflow Vulnerability

Source: MS
Type: UNKNOWN
MS02-033

Source: XF
Type: UNKNOWN
mscs-profile-service-bo(9423)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:commerce_server:2000:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:commerce_server:2000:sp1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:commerce_server:2000:sp2:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:commerce_server:2000:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:commerce_server:2002:*:*:*:*:*:*:*
  • AND
  • cpe:/o:microsoft:windows:2003_server:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_information_server:5.0:*:*:*:far_east:*:*:*

  • * Denotes that component is vulnerable
    BACK
    microsoft commerce server 2000
    microsoft commerce server 2000 sp1
    microsoft commerce server 2000 sp2
    microsoft commerce server 2000
    microsoft commerce server 2002
    microsoft windows 2003_server
    microsoft internet information server 5.0