CVE-2002-0862
Summary
| CVE | CVE-2002-0862 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-10-04 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Macos | - | All | All | All |
| Application | Microsoft | Internet Explorer | - | All | All | All |
| Application | Microsoft | Office | - | All | All | All |
| Application | Microsoft | Outlook Express | - | All | All | All |
| Operating System | Microsoft | Windows 2000 | - | All | All | All |
| Operating System | Microsoft | Windows 98 | - | All | All | All |
| Operating System | Microsoft | Windows 98se | - | All | All | All |
| Operating System | Microsoft | Windows Me | - | All | All | All |
| Operating System | Microsoft | Windows Nt | 4.0 | - | All | All |
| Operating System | Microsoft | Windows Nt | 4.0 | - | All | All |
| Operating System | Microsoft | Windows Xp | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Broken Link |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Broken Link |
| 'Insufficient Verification of Client Certificates in IIS 5.0 pre sp3' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Mailing List |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | Broken Link |
| Microsoft Security Bulletin MS02-050 - Important | Microsoft Docs | af854a3a-2127-422b-91ae-364da2661108 | docs.microsoft.com | Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | Third Party Advisory, VDB Entry |
| 'IE SSL Vulnerability' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Mailing List |
| 'IE SSL Exploit' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Mailing List |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.