CVE-2002-0366
Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.83%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 2.83% probability · 86th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 2000 · microsoft/windows nt · microsoft/windows xp
- Source
- cve@mitre.org
References
- http://online.securityfocus.com/archive/1/276776
- http://online.securityfocus.com/archive/1/278145
- http://www.nextgenss.com/vna/ms-ras.txtVendor Advisory
- http://www.securityfocus.com/bid/4852Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-029
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A61
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A63
- http://online.securityfocus.com/archive/1/276776
- http://online.securityfocus.com/archive/1/278145
- http://www.nextgenss.com/vna/ms-ras.txtVendor Advisory
- http://www.securityfocus.com/bid/4852Patch, Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-029
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A61
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A63
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.