Vulnerability Name: | CVE-2002-0699 (CCN-9982) |
Assigned: | 2002-08-28 |
Published: | 2002-08-28 |
Updated: | 2018-10-12 |
Summary: | Unknown vulnerability in the Certificate Enrollment ActiveX Control in Microsoft Windows 98, Windows 98 Second Edition, Windows Millennium, Windows NT 4.0, Windows 2000, and Windows XP allow remote attackers to delete digital certificates on a user's system via HTML.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): None Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-Other
|
Vulnerability Consequences: | Denial of Service |
References: | Source: MITRE Type: CNA CVE-2002-0699
Source: CCN Type: Microsoft Security Bulletin MS02-048 Flaw in Certificate Enrollment Control Could Allow Deletion of Digital Certificates (Q323172)
Source: CCN Type: OSVDB ID: 864 Microsoft Windows Certificate Enrollment ActiveX Arbitrary Certificate Deletion
Source: CCN Type: BID-5593 Microsoft ActiveX Certificate Enrollment Control Certificate Destruction Vulnerability
Source: MS Type: UNKNOWN MS02-048
Source: XF Type: UNKNOWN win-certificate-enrollment-dos(9982)
Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:190
|
Vulnerable Configuration: | Configuration 1: cpe:/o:microsoft:windows_2000:*:*:*:*:*:*:*:*OR cpe:/o:microsoft:windows_98:*:gold:*:*:*:*:*:*OR cpe:/o:microsoft:windows_98se:*:*:*:*:*:*:*:*OR cpe:/o:microsoft:windows_me:*:*:*:*:*:*:*:*OR cpe:/o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*OR cpe:/o:microsoft:windows_xp:*:gold:*:*:*:*:*:* Configuration CCN 1: cpe:/o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*OR cpe:/o:microsoft:windows_98:*:*:*:*:*:*:*:*OR cpe:/o:microsoft:windows_98se:*:*:*:*:*:*:*:*OR cpe:/o:microsoft:windows_2000:*:*:*:*:*:*:*:*OR cpe:/o:microsoft:windows_me:*:*:*:*:*:*:*:*OR cpe:/o:microsoft:windows:xp:*:*:*:*:*:*:*
Denotes that component is vulnerable |
Oval Definitions |
Definition ID | Class | Title | Last Modified |
---|
oval:org.mitre.oval:def:190 | V | ActiveX Certificate Enrollment Unauthorized Remote Certificate Deletion | 2011-05-16 |
|
BACK |