VulnerabilityModified
CVE-2004-2091
Microsoft Baseline Security Analyzer (MBSA) 1.2 does not correctly identify systems that have been patched but remain vulnerable to exploit until the system is rebooted, possibly giving the administrator a false sense of security.
MEDIUM 5.0EPSS 3.22%
Does this matter?
Lower severity and a low EPSS score (3.22%). Track it; it rarely justifies an emergency change on its own.
Description
Microsoft Baseline Security Analyzer (MBSA) 1.2 does not correctly identify systems that have been patched but remain vulnerable to exploit until the system is rebooted, possibly giving the administrator a false sense of security.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 3.22% probability · 87th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/baseline security analyzer
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/archive/1/353324Vendor Advisory
- http://www.securityfocus.com/bid/9634Vendor Advisory
- http://www.securityfocus.com/archive/1/353324Vendor Advisory
- http://www.securityfocus.com/bid/9634Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.