VulnerabilityModified
CVE-2002-0034
The Microsoft CONVERT.EXE program, when used on Windows 2000 and Windows XP systems, does not apply the default NTFS permissions when converting a FAT32 file system, which could cause the conversion to produce a file system with less secure permissions…
MEDIUM 4.6EPSS 1.95%
Does this matter?
Lower severity and a low EPSS score (1.95%). Track it; it rarely justifies an emergency change on its own.
Description
The Microsoft CONVERT.EXE program, when used on Windows 2000 and Windows XP systems, does not apply the default NTFS permissions when converting a FAT32 file system, which could cause the conversion to produce a file system with less secure permissions than expected.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.95% probability · 79th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 2000 · microsoft/windows xp
- Source
- cve@mitre.org
References
- http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3B237399
- http://www.kb.cert.org/vuls/id/361065Patch, Third Party Advisory, US Government Resource
- http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3B237399
- http://www.kb.cert.org/vuls/id/361065Patch, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.