Vulnerabilities > CVE-2002-0366 - Remote Access Service Buffer Overflow vulnerability in Microsoft Windows 2000, Windows NT and Windows XP

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
microsoft
nessus

Summary

Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.

Vulnerable Configurations

Part Description Count
OS
Microsoft
38

Nessus

NASL familyWindows : Microsoft Bulletins
NASL idSMB_NT_MS02-029.NASL
descriptionAn overflow in the RAS phonebook service allows a local user to execute code on the system with the privileges of LocalSystem.
last seen2020-06-01
modified2020-06-02
plugin id11029
published2002-06-13
reporterThis script is Copyright (C) 2002-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/11029
titleMS02-029: Windows RAS Local Overflow (318138)

Oval

  • accepted2018-09-11T10:00:00.000-05:00
    classvulnerability
    contributors
    • nameTiffany Bergeron
      organizationThe MITRE Corporation
    • nameJonathan Baker
      organizationThe MITRE Corporation
    definition_extensions
    commentMicrosoft Windows NT is installed
    ovaloval:org.mitre.oval:def:36
    descriptionBuffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.
    familywindows
    idoval:org.mitre.oval:def:61
    statusaccepted
    submitted2003-04-04T12:00:00.000-04:00
    titleWindows NT Remote Access Service Phonebook Buffer Overflow
    version70
  • accepted2011-05-16T04:03:18.751-04:00
    classvulnerability
    contributors
    • nameTiffany Bergeron
      organizationThe MITRE Corporation
    • nameShane Shaffer
      organizationG2, Inc.
    • nameSudhir Gandhe
      organizationTelos
    • nameShane Shaffer
      organizationG2, Inc.
    descriptionBuffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.
    familywindows
    idoval:org.mitre.oval:def:63
    statusaccepted
    submitted2003-04-04T12:00:00.000-04:00
    titleWindows 2000 Remote Access Service Phonebook Buffer Overflow
    version69