First published: Tue Nov 12 2002(Updated: )
The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain privileges as other users via Trojan horse programs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows NT | =4.0-sp5 | |
Microsoft Windows NT | =4.0-sp3 | |
Microsoft Windows NT | =4.0-sp6a | |
Microsoft Windows 2000 | ||
Microsoft Windows NT | =4.0 | |
Microsoft Windows NT | =4.0-sp1 | |
Microsoft Windows NT | =4.0-sp3 | |
Microsoft Windows NT | =4.0-sp6 | |
Microsoft Windows NT | =4.0-sp4 | |
Microsoft Windows NT | =4.0-sp5 | |
Microsoft Windows 2000 | =sp2 | |
Microsoft Windows NT | =4.0-sp6 | |
Microsoft Windows NT | =4.0 | |
Microsoft Windows NT | =4.0-sp2 | |
Microsoft Windows NT | =4.0-sp6a | |
Microsoft Windows NT | =4.0-sp4 | |
Microsoft Windows NT | =4.0-sp2 | |
Microsoft Windows 2000 | =sp1 | |
Microsoft Windows NT | =4.0-sp4 | |
Microsoft Windows NT | =4.0-sp6 | |
Microsoft Windows NT | =4.0-sp3 | |
Microsoft Windows NT | =4.0-sp1 | |
Microsoft Windows NT | =4.0-sp1 | |
Microsoft Windows NT | =4.0 | |
Microsoft Windows NT | =4.0-sp6a | |
Microsoft Windows NT | =4.0-sp5 | |
Microsoft Windows NT | =4.0-sp2 | |
Microsoft Windows 2000 | =sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1184 is considered a moderate severity vulnerability that could allow unauthorized privilege escalation.
To fix CVE-2002-1184, you should apply the necessary security patches provided by Microsoft for affected Windows versions.
CVE-2002-1184 affects various versions of Microsoft Windows NT and Windows 2000, particularly those with default permissions on the system root folder.
While CVE-2002-1184 primarily allows for local privilege escalation, it can indirectly lead to remote access if an attacker gains higher privileges.
You can determine if your system is vulnerable to CVE-2002-1184 by checking the permissions on the system root folder and ensuring that appropriate security patches are installed.