VulnerabilityModified
CVE-2002-2126
restrictEnabled in Integrity Protection Driver (IPD) 1.2 delays driver installation for 20 minutes, which allows local users to insert malicious code by setting system clock to an earlier time.
LOW 2.1EPSS 0.43%
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
restrictEnabled in Integrity Protection Driver (IPD) 1.2 delays driver installation for 20 minutes, which allows local users to insert malicious code by setting system clock to an earlier time.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 0.43% probability · 37th percentile
- CISA KEV
- Not listed
- Affected
- pedestal software/integrity protection driver
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2002-12/0021.htmlExploit, Patch
- http://archives.neohapsis.com/archives/ntbugtraq/2002-q4/0087.htmlPatch
- http://www.iss.net/security_center/static/10745.phpPatch
- http://www.securityfocus.com/bid/6295Patch
- http://archives.neohapsis.com/archives/bugtraq/2002-12/0021.htmlExploit, Patch
- http://archives.neohapsis.com/archives/ntbugtraq/2002-q4/0087.htmlPatch
- http://www.iss.net/security_center/static/10745.phpPatch
- http://www.securityfocus.com/bid/6295Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.