SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2002-0862

The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for…

MEDIUM 6.8EPSS 15.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 15.8%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.

Description

The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
15.76% probability · 97th percentile
CISA KEV
Not listed
Weakness
CWE-295
Affected
microsoft/windows 2000 · microsoft/windows 98 · microsoft/windows 98se · microsoft/windows me · microsoft/windows nt · microsoft/windows xp · microsoft/internet explorer · microsoft/office · microsoft/outlook express
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.