CVE-2002-1932
Microsoft Windows XP and Windows 2000, when configured to send administrative alerts and the "Do not overwrite events (clear log manually)" option is set, does not notify the administrator when the log reaches its maximum size, which allows local users…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.8%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Windows XP and Windows 2000, when configured to send administrative alerts and the "Do not overwrite events (clear log manually)" option is set, does not notify the administrator when the log reaches its maximum size, which allows local users and remote attackers to avoid detection.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 12.78% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 2000 · microsoft/windows xp
- Source
- cve@mitre.org
References
- http://online.securityfocus.com/archive/1/295341
- http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3B329350
- http://www.iss.net/security_center/static/10377.phpPatch
- http://www.securityfocus.com/bid/5972Patch
- http://online.securityfocus.com/archive/1/295341
- http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3B329350
- http://www.iss.net/security_center/static/10377.phpPatch
- http://www.securityfocus.com/bid/5972Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.