CVE-2002-0869
Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 23.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation."
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 23.64% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/internet information server · microsoft/internet information services
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0059.html
- http://marc.info/?l=bugtraq&m=103642839205574&w=2
- http://www.ciac.org/ciac/bulletins/n-011.shtml
- http://www.iss.net/security_center/static/10502.phpPatch, Vendor Advisory
- http://www.li0n.pe.kr/eng/advisory/ms/iis_impersonation.txt
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-062
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A929
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A930
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A983
- http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0059.html
- http://marc.info/?l=bugtraq&m=103642839205574&w=2
- http://www.ciac.org/ciac/bulletins/n-011.shtml
- http://www.iss.net/security_center/static/10502.phpPatch, Vendor Advisory
- http://www.li0n.pe.kr/eng/advisory/ms/iis_impersonation.txt
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-062
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A929
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A930
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A983
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.