CVE-2002-1184
The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to…
Does this matter?
Lower severity and a low EPSS score (2.76%). Track it; it rarely justifies an emergency change on its own.
Description
The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain privileges as other users via Trojan horse programs.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 2.76% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 2000 · microsoft/windows nt
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/5415
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-064
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9779
- http://www.securityfocus.com/bid/5415
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-064
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9779
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.