CVE-2002-0228
Microsoft MSN Messenger allows remote attackers to use Javascript that references an ActiveX object to obtain sensitive information such as display names and web site navigation, and possibly more when the user is connected to certain Microsoft sites…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 19.9%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft MSN Messenger allows remote attackers to use Javascript that references an ActiveX object to obtain sensitive information such as display names and web site navigation, and possibly more when the user is connected to certain Microsoft sites (or DNS-spoofed sites).
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 19.87% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/msn messenger
- Source
- cve@mitre.org
References
- http://online.securityfocus.com/archive/1/254021Patch, Vendor Advisory
- http://www.iss.net/security_center/static/8084.phpVendor Advisory
- http://www.securityfocus.com/bid/4028
- http://online.securityfocus.com/archive/1/254021Patch, Vendor Advisory
- http://www.iss.net/security_center/static/8084.phpVendor Advisory
- http://www.securityfocus.com/bid/4028
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.