PT-2002-3113 · Microsoft · Windows 2000+2

Published

2002-12-31

·

Updated

2019-04-30

·

CVE-2002-2401

CVSS v2.0

3.6

Low

VectorAV:L/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Windows NT Virtual DOS Machine (NTVDM.EXE) versions in Windows 2000, NT, and XP
Description The issue allows local users to bypass the loader and execute arbitrary programs due to the lack of verification of user execution permissions for 16-bit executable files.
Recommendations For Windows 2000, NT, and XP, consider restricting access to 16-bit executable files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2002-2401

Affected Products

Windows 2000
Windows Nt
Windows Xp