SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2002-0034

The Microsoft CONVERT.EXE program, when used on Windows 2000 and Windows XP systems, does not apply the default NTFS permissions when converting a FAT32 file system, which could cause the conversion to produce a file system with less secure permissions…

MEDIUM 4.6EPSS 1.95%

Does this matter?

Lower severity and a low EPSS score (1.95%). Track it; it rarely justifies an emergency change on its own.

Description

The Microsoft CONVERT.EXE program, when used on Windows 2000 and Windows XP systems, does not apply the default NTFS permissions when converting a FAT32 file system, which could cause the conversion to produce a file system with less secure permissions than expected.

CVSS 2.0
4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
EPSS
1.95% probability · 79th percentile
CISA KEV
Not listed
Affected
microsoft/windows 2000 · microsoft/windows xp
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.