First published: Fri Mar 08 2002(Updated: )
In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows NT | ||
Microsoft Windows 2000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0018 is classified as a critical vulnerability due to the potential for remote attackers to gain Domain Administrator privileges.
To remediate CVE-2002-0018, ensure that all trusted domains properly authenticate all listed SIDs to prevent unauthorized privilege escalation.
CVE-2002-0018 affects Microsoft Windows NT and Microsoft Windows 2000.
The potential impact of CVE-2002-0018 includes unauthorized elevation of privileges to Domain Administrator level, compromising the network security.
There is no patch available for CVE-2002-0018 since it pertains to outdated operating systems, but review security policies and configurations as mitigation measures.