Vulnerability Name: | CVE-2002-0869 (CCN-10502) | ||||||||||||||||
Assigned: | 2002-10-30 | ||||||||||||||||
Published: | 2002-10-30 | ||||||||||||||||
Updated: | 2020-11-23 | ||||||||||||||||
Summary: | Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation." | ||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||
References: | Source: VULNWATCH Type: UNKNOWN 20021104 [A3SC] MS IIS out of process privilege elevation vulnerability(A3CR@K-Vul-2002-06-002) Source: MITRE Type: CNA CVE-2002-0869 Source: BUGTRAQ Type: UNKNOWN 20021104 [A3SC] MS IIS out of process privilege elevation vulnerability(A3CR@K-Vul-2002-06-002) Source: CCN Type: CIAC Information Bulletin N-011 Cumulative Patch for Internet Information Service Source: CIAC Type: UNKNOWN N-011 Source: XF Type: Patch, Vendor Advisory iis-outofprocess-privilege-elevation(10502) Source: CCN Type: A3 Security Consulting: CR@K Vulnerability Research MS IIS out of process privilege elevation vulnerability(A3CR@K-Vul-2002-06-002) Source: MISC Type: UNKNOWN http://www.li0n.pe.kr/eng/advisory/ms/iis_impersonation.txt Source: CCN Type: Microsoft Security Bulletin MS02-062 Cumulative Patch for Internet Information Service (Q327696) Source: CCN Type: Microsoft Security Bulletin MS03-018 Cumulative Patch for Internet Information Service (811114) Source: CCN Type: BID-6068 Multiple Microsoft IIS Vulnerabilities Source: CCN Type: BID-6069 Microsoft IIS Out Of Process Privilege Escalation Vulnerability Source: MS Type: UNKNOWN MS02-062 Source: XF Type: UNKNOWN iis-outofprocess-privilege-elevation(10502) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:929 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:930 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:983 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |