First published: Fri Mar 08 2002(Updated: )
Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Exchange Server | =2000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0049 is considered a medium severity vulnerability due to its potential for unauthorized access to the system registry.
To fix CVE-2002-0049, restrict the permissions on the WinReg key to prevent the "Everyone" group from having read or modify access.
CVE-2002-0049 affects Microsoft Exchange Server 2000.
CVE-2002-0049 allows remote attackers to read or modify critical registry keys, which could lead to further exploitation of the system.
There is no specific patch for CVE-2002-0049, but securing the registry permissions is recommended as a mitigation strategy.