CVE-2002-0862
The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.8%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 15.76% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-295
- Affected
- microsoft/windows 2000 · microsoft/windows 98 · microsoft/windows 98se · microsoft/windows me · microsoft/windows nt · microsoft/windows xp · microsoft/internet explorer · microsoft/office · microsoft/outlook express
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=102866120821995&w=2Mailing List
- http://marc.info/?l=bugtraq&m=102918200405308&w=2Mailing List
- http://marc.info/?l=bugtraq&m=102976967730450&w=2Mailing List
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-050Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9776Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1056Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1332Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2671Broken Link
- http://marc.info/?l=bugtraq&m=102866120821995&w=2Mailing List
- http://marc.info/?l=bugtraq&m=102918200405308&w=2Mailing List
- http://marc.info/?l=bugtraq&m=102976967730450&w=2Mailing List
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-050Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9776Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1056Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1332Broken Link
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2671Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.