CVE-2002-0862
The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.
- Affected products
- Internet Explorer For Mac, Office For Mac, Outlook Express For Mac, Windows
- Microsoft Windows 2000
- All versions
- Microsoft Windows 98
- All versions
- Microsoft Windows 98se
- All versions
- Microsoft Windows Me
- All versions
- Microsoft Windows Nt
- = 4.0
- Microsoft Windows Xp
- All versions
- Fix
- Available
- CVSS 2.0
- 6.8 MEDIUM
- EPSS
- 15.8% (97th percentile)
- Weakness
- CWE-295
- NVD status
- Modified
- Published
- 2002-09-10
CVE-2002-0862 at NVD
1 known exploit for CVE-2002-0862
Proof-of-concept code and exploit modules indexed by Sploitus