CVE-2002-0866
Java Database Connectivity (JDBC) classes in Microsoft Virtual Machine (VM) up to and including 5.0.3805 allow remote attackers to load and execute DLLs (dynamic link libraries) via a Java applet that calls the constructor for com.ms.jdbc.odbc.JdbcOdbc…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 41.4%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Java Database Connectivity (JDBC) classes in Microsoft Virtual Machine (VM) up to and including 5.0.3805 allow remote attackers to load and execute DLLs (dynamic link libraries) via a Java applet that calls the constructor for com.ms.jdbc.odbc.JdbcOdbc with the desired DLL terminated by a null string, aka "DLL Execution via JDBC Classes."
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 41.36% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/virtual machine
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2002-09/0271.html
- http://www.iss.net/security_center/static/10133.phpPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/307306Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/5751
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-052
- http://archives.neohapsis.com/archives/bugtraq/2002-09/0271.html
- http://www.iss.net/security_center/static/10133.phpPatch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/307306Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/5751
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-052
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.