First published: Tue Dec 31 2002(Updated: )
Novell Netware 5.0 through 5.1 may allow local users to gain "Domain Admin" rights by logging into a Novell Directory Services (NDS) account, and executing "net use" on an NDS_ADM account that is not in the NT domain but has domain access rights, which allows the user to enter a null password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell NetWare | =5.1 | |
Novell NetWare | =5.0-sp5 | |
Novell NetWare | =5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1772 is considered a high severity vulnerability due to its potential to grant local users Domain Admin rights.
To fix CVE-2002-1772, update Novell Netware to the latest version or apply the necessary patches that address this vulnerability.
CVE-2002-1772 affects local users of Novell Netware versions 5.0 and 5.1 who have access to NDS_ADM accounts.
CVE-2002-1772 cannot be exploited remotely as it requires local user access to the system.
Systems running Novell Netware 5.0 and 5.1 are vulnerable to CVE-2002-1772.