CVE-2002-2324
The "System Restore" directory and subdirectories, and possibly other subdirectories in the "System Volume Information" directory on Windows XP Professional, have insecure access control list (ACL) permissions, which allows local users to access…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.77%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The "System Restore" directory and subdirectories, and possibly other subdirectories in the "System Volume Information" directory on Windows XP Professional, have insecure access control list (ACL) permissions, which allows local users to access restricted files and modify registry settings.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 1.77% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- microsoft/windows xp
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0070.htmlExploit
- http://www.iss.net/security_center/static/10279.php
- http://www.securityfocus.com/bid/5894
- http://archives.neohapsis.com/archives/bugtraq/2002-10/0070.htmlExploit
- http://www.iss.net/security_center/static/10279.php
- http://www.securityfocus.com/bid/5894
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.