CVE Vulnerabilities

CVE-2002-0421

Published: Aug 12, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IIS 4.0 allows local users to bypass the User cannot change password policy for Windows NT by directly calling .htr password changing programs in the /iisadmpwd directory, including (1) aexp2.htr, (2) aexp2b.htr, (3) aexp3.htr , or (4) aexp4.htr.

Affected Software

NameVendorStart VersionEnd Version
Windows_ntMicrosoft4.0 (including)4.0 (including)
Windows_ntMicrosoft4.0-sp1 (including)4.0-sp1 (including)
Windows_ntMicrosoft4.0-sp2 (including)4.0-sp2 (including)
Windows_ntMicrosoft4.0-sp3 (including)4.0-sp3 (including)
Windows_ntMicrosoft4.0-sp4 (including)4.0-sp4 (including)
Windows_ntMicrosoft4.0-sp5 (including)4.0-sp5 (including)
Windows_ntMicrosoft4.0-sp6 (including)4.0-sp6 (including)
Windows_ntMicrosoft4.0-sp6a (including)4.0-sp6a (including)

References