7.5

CVE-2002-0694

The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed, aka "Code Execution via Compiled HTML Help File."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2000 Update sp1
Microsoft ≫ Windows 2000 Update sp2
Microsoft ≫ Windows 2000 Update sp3
Microsoft ≫ Windows 98 Update gold
Microsoft ≫ Windows Nt Version 4.0 Edition enterprise_server
Microsoft ≫ Windows Nt Version 4.0 Edition server
Microsoft ≫ Windows Nt Version 4.0 Edition terminal_server
Microsoft ≫ Windows Nt Version 4.0 Edition workstation
Microsoft ≫ Windows Nt Version 4.0 Update sp1 Edition enterprise_server
Microsoft ≫ Windows Nt Version 4.0 Update sp1 Edition server
Microsoft ≫ Windows Nt Version 4.0 Update sp1 Edition terminal_server
Microsoft ≫ Windows Nt Version 4.0 Update sp1 Edition workstation
Microsoft ≫ Windows Nt Version 4.0 Update sp2 Edition enterprise_server
Microsoft ≫ Windows Nt Version 4.0 Update sp2 Edition server
Microsoft ≫ Windows Nt Version 4.0 Update sp2 Edition terminal_server
Microsoft ≫ Windows Nt Version 4.0 Update sp2 Edition workstation
Microsoft ≫ Windows Nt Version 4.0 Update sp3 Edition enterprise_server
Microsoft ≫ Windows Nt Version 4.0 Update sp3 Edition server
Microsoft ≫ Windows Nt Version 4.0 Update sp3 Edition terminal_server
Microsoft ≫ Windows Nt Version 4.0 Update sp3 Edition workstation
Microsoft ≫ Windows Nt Version 4.0 Update sp4 Edition enterprise_server
Microsoft ≫ Windows Nt Version 4.0 Update sp4 Edition server
Microsoft ≫ Windows Nt Version 4.0 Update sp4 Edition terminal_server
Microsoft ≫ Windows Nt Version 4.0 Update sp4 Edition workstation
Microsoft ≫ Windows Nt Version 4.0 Update sp5 Edition enterprise_server
Microsoft ≫ Windows Nt Version 4.0 Update sp5 Edition server
Microsoft ≫ Windows Nt Version 4.0 Update sp5 Edition terminal_server
Microsoft ≫ Windows Nt Version 4.0 Update sp5 Edition workstation
Microsoft ≫ Windows Nt Version 4.0 Update sp6 Edition enterprise_server
Microsoft ≫ Windows Nt Version 4.0 Update sp6 Edition server
Microsoft ≫ Windows Nt Version 4.0 Update sp6 Edition terminal_server
Microsoft ≫ Windows Nt Version 4.0 Update sp6 Edition workstation
Microsoft ≫ Windows Nt Version 4.0 Update sp6a Edition enterprise_server
Microsoft ≫ Windows Nt Version 4.0 Update sp6a Edition server
Microsoft ≫ Windows Nt Version 4.0 Update sp6a Edition terminal_server
Microsoft ≫ Windows Nt Version 4.0 Update sp6a Edition workstation
Microsoft ≫ Windows Xp Edition home
Microsoft ≫ Windows Xp Update gold Edition professional
Microsoft ≫ Windows Xp Update sp1 Edition home
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 13.74% 0.961
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-055
http://www.iss.net/security_center/static/10254.php
Vendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A403