MEDIUM · 6.8

CVE-2002-0862

The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac...

Vulnerability Description

The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.

CVSS Score

6.8

MEDIUM

AV:N/AC:M/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
MicrosoftWindows 2000-
MicrosoftWindows 98-
MicrosoftWindows 98Se-
MicrosoftWindows Me-
MicrosoftWindows Nt4.0
MicrosoftWindows Xp-
MicrosoftInternet Explorer-
MicrosoftOffice-
MicrosoftOutlook Express-
AppleMacos-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2002-0862?

CVE-2002-0862 is a vulnerability with a CVSS score of 6.8 (MEDIUM). The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac...

How severe is CVE-2002-0862?

CVE-2002-0862 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-0862?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows 2000, Microsoft Windows 98, Microsoft Windows 98Se, Microsoft Windows Me, Microsoft Windows Nt.