Vulnerability Name:
CVE-2002-2028 (CCN-1976)
Assigned:
1999-01-01
Published:
1999-01-01
Updated:
2019-04-30
Summary:
The screensaver on Windows NT 4.0, 2000, XP, and 2002 does not verify if a domain account has already been locked when a valid password is provided, which makes it easier for users with physical access to conduct brute force password guessing.
CVSS v3 Severity:
4.0 Medium
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
)
Exploitability Metrics:
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
Low
Integrity (I):
None
Availibility (A):
None
CVSS v2 Severity:
2.1 Low
(CVSS v2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
)
Exploitability Metrics:
Access Vector (AV):
Local
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
None
Availibility (A):
None
2.1 Low
(CCN CVSS v2 Vector:
AV:L/AC:L/Au:N/C:P/I:N/A:N
)
Exploitability Metrics:
Access Vector (AV):
Local
Access Complexity (AC):
Low
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
None
Availibility (A):
None
Vulnerability Type:
CWE-Other
Vulnerability Consequences:
Bypass Security
References:
Source: BUGTRAQ
Type: UNKNOWN
20020121 The "Lunch Break Hole"
Source: MITRE
Type: CNA
CVE-2002-2028
Source: MSKB
Type: Vendor Advisory
Q188700
Source: MISC
Type: Vendor Advisory
http://www.heysoft.de/nt/lbh.htm
Source: CCN
Type: OSVDB ID: 59732
Microsoft Windows Screensaver Domain Account Lock Verification Local Brute Force Weakness
Source: BID
Type: UNKNOWN
3933
Source: CCN
Type: BID-3933
Microsoft Windows Inaccurate Login Logging Vulnerability
Source: XF
Type: UNKNOWN
nt-gina-lockout(1976)
Source: CCN
Type: Microsoft Knowledge Base Article 188700
Screensaver Password Works Even if Account Is Locked Out
Vulnerable Configuration:
Configuration 1
:
cpe:/o:microsoft:windows_2000:*:*:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_2000:*:sp1:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_2000:*:sp2:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_nt:4.0:*:enterprise_server:*:*:*:*:*
OR
cpe:/o:microsoft:windows_nt:4.0:*:server:*:*:*:*:*
OR
cpe:/o:microsoft:windows_nt:4.0:*:terminal_server:*:*:*:*:*
OR
cpe:/o:microsoft:windows_nt:4.0:*:workstation:*:*:*:*:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp1:enterprise_server:*:*:*:*:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp1:*:*:server:*:x86:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp1:*:*:terminal_server:*:x86:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp1:*:*:workstation:*:x86:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp2:enterprise_server:*:*:*:*:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp2:*:*:server:*:x86:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp2:*:*:terminal_server:*:x86:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp2:*:*:workstation:*:x86:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp3:enterprise_server:*:*:*:*:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp3:*:*:server:*:x86:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp3:*:*:terminal_server:*:x86:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp3:*:*:workstation:*:x86:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp4:enterprise_server:*:*:*:*:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp4:*:*:server:*:x86:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp4:*:*:terminal_server:*:x86:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp4:*:*:workstation:*:x86:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp5:enterprise_server:*:*:*:*:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp5:*:*:server:*:x86:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp5:*:*:terminal_server:*:x86:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp5:*:*:workstation:*:x86:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp6a:enterprise_server:*:*:*:*:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp6a:*:*:server:*:x86:*
OR
cpe:/o:microsoft:windows_nt:4.0:sp6a:*:*:workstation:*:x86:*
OR
cpe:/o:microsoft:windows_xp:*:gold:professional:*:*:*:*:*
Configuration CCN 1
:
cpe:/o:microsoft:windows_nt:3.51:*:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_nt:4.0:*:*:*:*:*:*:*
OR
cpe:/o:microsoft:windows_nt:3.5.1:sp4:*:*:*:*:*:*
Denotes that component is vulnerable
BACK
microsoft
windows 2000 *
microsoft
windows 2000 * sp1
microsoft
windows 2000 * sp2
microsoft
windows nt 4.0
microsoft
windows nt 4.0
microsoft
windows nt 4.0
microsoft
windows nt 4.0
microsoft
windows nt 4.0 sp1
microsoft
windows nt 4.0 sp1
microsoft
windows nt 4.0 sp1
microsoft
windows nt 4.0 sp1
microsoft
windows nt 4.0 sp2
microsoft
windows nt 4.0 sp2
microsoft
windows nt 4.0 sp2
microsoft
windows nt 4.0 sp2
microsoft
windows nt 4.0 sp3
microsoft
windows nt 4.0 sp3
microsoft
windows nt 4.0 sp3
microsoft
windows nt 4.0 sp3
microsoft
windows nt 4.0 sp4
microsoft
windows nt 4.0 sp4
microsoft
windows nt 4.0 sp4
microsoft
windows nt 4.0 sp4
microsoft
windows nt 4.0 sp5
microsoft
windows nt 4.0 sp5
microsoft
windows nt 4.0 sp5
microsoft
windows nt 4.0 sp5
microsoft
windows nt 4.0 sp6a
microsoft
windows nt 4.0 sp6a
microsoft
windows nt 4.0 sp6a
microsoft
windows xp * gold
microsoft
windows nt 3.51
microsoft
windows nt 4.0
microsoft
windows nt 3.5.1 sp4