First published: Tue Dec 31 2002(Updated: )
Microsoft Baseline Security Analyzer (MBSA) 1.0 stores security scans in a known location C:\Documents and Settings\username\SecurityScans in plaintext, which could allow remote attackers to obtain sensitive information about the system via malicious active content such as ActiveX controls or Java.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Baseline Security Analyzer | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2002-1762 is considered to be medium, as it allows remote attackers to obtain sensitive information.
To fix CVE-2002-1762, it's recommended to ensure that security scan files stored by MBSA are not accessible by arbitrary users or to upgrade to a more secure version of the software.
CVE-2002-1762 can be exploited by attackers utilizing malicious active content such as ActiveX controls or Java.
CVE-2002-1762 affects Microsoft Baseline Security Analyzer version 1.0.
CVE-2002-1762 can potentially leak sensitive information about the system through the plaintext security scan files.