First published: Tue Jun 11 2002(Updated: )
IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr password changing programs in the /iisadmpwd directory, including (1) aexp2.htr, (2) aexp2b.htr, (3) aexp3.htr , or (4) aexp4.htr.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows NT | =4.0 | |
Microsoft Windows NT | =4.0-sp1 | |
Microsoft Windows NT | =4.0-sp3 | |
Microsoft Windows NT | =4.0-sp6 | |
Microsoft Windows NT | =4.0-sp4 | |
Microsoft Windows NT | =4.0-sp6a | |
Microsoft Windows NT | =4.0-sp2 | |
Microsoft Windows NT | =4.0-sp5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0421 has a moderate severity level due to the potential for local users to bypass password policies.
To remediate CVE-2002-0421, restrict access to the /iisadmpwd directory and properly configure user permissions.
CVE-2002-0421 affects all versions of Windows NT 4.0, including various service packs.
CVE-2002-0421 is a local privilege escalation vulnerability.
CVE-2002-0421 cannot be exploited by remote users as it requires local access.