PT-2002-2653 · Microsoft · Windows 2000+1

Published

2002-12-31

·

Updated

2019-04-30

·

CVE-2002-1932

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Windows XP and Windows 2000
Description The issue concerns a configuration where administrative alerts are sent and the option to not overwrite events is set. In this setup, when the log reaches its maximum size, no notification is sent to the administrator. This allows local users and remote attackers to potentially avoid detection.
Recommendations For Microsoft Windows XP and Windows 2000, consider disabling the "Do not overwrite events (clear log manually)" option to ensure logs are properly managed and notifications are sent when the log reaches its maximum size. Additionally, regularly monitor and clear logs manually to prevent them from reaching maximum size and to ensure administrative alerts are effective.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1932

Affected Products

Windows 2000
Windows Xp