CVE Vulnerabilities

CVE-2002-0049

Improper Privilege Management

Published: Mar 08, 2002 | Modified: Apr 02, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Microsoft Exchange Server 2000 System Attendant gives Everyone group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Exchange_server Microsoft 2000 2000

Potential Mitigations

References