Sploitus

CVE-2002-0862

1 known exploit for CVE-2002-0862

The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.

Microsoft Windows 2000
All versions
Microsoft Windows 98
All versions
Microsoft Windows 98se
All versions
Microsoft Windows Me
All versions
Microsoft Windows Nt
= 4.0
Microsoft Windows Xp
All versions
Fix
Available
CVSS 2.0
6.8 MEDIUM
EPSS
15.8% (97th percentile)
Weakness
CWE-295
NVD status
Modified
Published
2002-09-10
CVE-2002-0862 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2002-0862

Proof-of-concept code and exploit modules indexed by Sploitus