Vulnerabilities > CVE-2002-1183 - Unspecified vulnerability in Microsoft Windows 98, Windows 98Se and Windows NT
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862).
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 3 |
Exploit-Db
description | MS IE 5/6,Konqueror 2.2.2/3.0,Weblogic Server 5/6/7 Invalid X.509 Certificate Chain. CVE-2002-0828,CVE-2002-0862,CVE-2002-1183. Remote exploit for windows pl... |
id | EDB-ID:21692 |
last seen | 2016-02-02 |
modified | 2002-08-06 |
published | 2002-08-06 |
reporter | Mike Benham |
source | https://www.exploit-db.com/download/21692/ |
title | Microsoft Internet Explorer 5/6,Konqueror 2.2.2/3.0,Weblogic Server 5/6/7 Invalid X.509 Certificate Chain |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS02-050.NASL |
description | The remote host contains a version of the CryptoAPI that could allow an attacker to spoof the identity of another user with malformed SSL certificates. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11145 |
published | 2002-10-24 |
reporter | This script is Copyright (C) 2002-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11145 |
title | MS02-050: Certificate Validation Flaw Could Enable Identity Spoofing (328145) |
code |
|
Oval
accepted 2008-03-24T04:00:11.447-04:00 class vulnerability contributors name Christine Walzer organization The MITRE Corporation name Christine Walzer organization The MITRE Corporation name Christine Walzer organization The MITRE Corporation name Christine Walzer organization The MITRE Corporation name Jonathan Baker organization The MITRE Corporation
definition_extensions comment Microsoft Windows NT is installed oval oval:org.mitre.oval:def:36 description Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862). family windows id oval:org.mitre.oval:def:1059 status accepted submitted 2004-07-12T12:00:00.000-04:00 title Microsoft Certificate Validation Flaw Identity Spoofing Vulnerability (Variant) version 73 accepted 2008-03-24T04:00:14.956-04:00 class vulnerability contributors name Christine Walzer organization The MITRE Corporation name Christine Walzer organization The MITRE Corporation name Christine Walzer organization The MITRE Corporation name Christine Walzer organization The MITRE Corporation name John Hoyland organization Centennial Software name Jonathan Baker organization The MITRE Corporation
definition_extensions comment Microsoft Windows NT is installed oval oval:org.mitre.oval:def:36 description Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862). family windows id oval:org.mitre.oval:def:1455 status accepted submitted 2004-07-12T12:00:00.000-04:00 title Windows NT Certificate Validation Identity Spoofing Vulnerability (Test 1) version 73 accepted 2008-03-24T04:00:21.402-04:00 class vulnerability contributors name Christine Walzer organization The MITRE Corporation name Christine Walzer organization The MITRE Corporation name Christine Walzer organization The MITRE Corporation name Christine Walzer organization The MITRE Corporation name Jonathan Baker organization The MITRE Corporation
definition_extensions comment Microsoft Windows NT is installed oval oval:org.mitre.oval:def:36 description Microsoft Windows 98 and Windows NT 4.0 do not properly verify the Basic Constraints of digital certificates, allowing remote attackers to execute code, aka "New Variant of Certificate Validation Flaw Could Enable Identity Spoofing" (CAN-2002-0862). family windows id oval:org.mitre.oval:def:2108 status accepted submitted 2004-07-12T12:00:00.000-04:00 title Windows NT Certificate Validation Identity Spoofing Vulnerability (Test 2) version 72
References
- http://www.securityfocus.com/bid/5410
- http://www.securityfocus.com/bid/5410
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-050
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-050
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9776
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9776
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1059
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1059
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1455
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1455
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2108
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2108