VulnerabilityModified
CVE-2002-0049
Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys.
MEDIUM 6.4EPSS 13.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.3%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 13.30% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- microsoft/exchange server
- Source
- cve@mitre.org
References
- http://www.osvdb.org/2042Broken Link
- http://www.securityfocus.com/bid/4053Patch, Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-003Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8092Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1022Third Party Advisory
- http://www.osvdb.org/2042Broken Link
- http://www.securityfocus.com/bid/4053Patch, Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-003Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/8092Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1022Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.