CVE-2002-0724
Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2)…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 25.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in SMB (Server Message Block) protocol in Microsoft Windows NT, Windows 2000, and Windows XP allows attackers to cause a denial of service (crash) via a SMB_COM_TRANSACTION packet with a request for the (1) NetShareEnum, (2) NetServerEnum2, or (3) NetServerEnum3, aka "Unchecked Buffer in Network Share Provider Can Lead to Denial of Service".
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 25.69% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 2000 · microsoft/windows nt · microsoft/windows xp
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=103011556323184&w=2
- http://www.kb.cert.org/vuls/id/250635Patch, Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/311619US Government Resource
- http://www.kb.cert.org/vuls/id/342243US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-045
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A189
- http://marc.info/?l=bugtraq&m=103011556323184&w=2
- http://www.kb.cert.org/vuls/id/250635Patch, Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/311619US Government Resource
- http://www.kb.cert.org/vuls/id/342243US Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-045
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A189
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.