5
CVE-2002-1256
- EPSS 5.41%
- Veröffentlicht 23.12.2002 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:59:00
- Erkennungen
The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digital signing settings in an SMB session to force the data to be sent unsigned, then inject data into the session without detection, e.g. by modifying group policy information sent from a domain controller.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2000 Update sp1
Microsoft ≫ Windows 2000 Update sp2
Microsoft ≫ Windows 2000 Update sp3
Microsoft ≫ Windows 2000 Terminal Services Update sp1
Microsoft ≫ Windows 2000 Terminal Services Update sp2
Microsoft ≫ Windows 2000 Terminal Services Update sp3
Microsoft ≫ Windows Xp Edition 64-bit
Microsoft ≫ Windows Xp Edition home
Microsoft ≫ Windows Xp Update gold Edition professional
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.41% | 0.918 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
http://www.securityfocus.com/bid/6367
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-070
https://exchange.xforce.ibmcloud.com/vulnerabilities/10843
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A277