Executive Summary
Informations | |||
---|---|---|---|
Name | MS02-069 | First vendor Publication | N/A |
Vendor | Microsoft | Last vendor Modification | N/A |
Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 10 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Flaw in Microsoft VM Could Enable System Compromise (810030) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:582 | |||
Oval ID: | oval:org.mitre.oval:def:582 | ||
Title: | MSJava Applet CODEBASE File Access Vulnerability | ||
Description: | Two vulnerabilities in Microsoft Virtual Machine (VM) up to and including build 5.0.3805, as used in Internet Explorer and other applications, allow remote attackers to read files via a Java applet with a spoofed location in the CODEBASE parameter in the APPLET tag, possibly due to a parsing error. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2002-1258 | Version: | 1 |
Platform(s): | Microsoft Windows 98 Microsoft Windows ME Microsoft Windows NT Microsoft Windows 2000 Microsoft Windows XP | Product(s): | Microsoft Virtual Machine (VM) |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2005-11-03 | Name : Flaw in Microsoft VM Could Allow Code Execution (810030) File : nvt/smb_nt_ms02-052.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
13418 | Microsoft Virtual Machine Applet Tag Malformed CODEBASE Arbitrary File Access |
13417 | Microsoft Virtual Machine COM Object Arbitrary Code Execution Microsoft Java Virtual Machine allows untrusted Java applets to access COM (Component Object Model) objects. An attack may be able to compromise a vulnerable system by including a malicious Java applet that will execute arbitrary code via COM. Normally only trusted Java applets should be able to access COM objects. |
13412 | Microsoft Virtual Machine user.dir Property Information Disclosure |
11914 | Microsoft Virtual Machine JDBC API Remote Security Check Bypass Microsoft Virtual Machine contains a flaw that may allow a malicious user to gain unauthorized access to database. The issue is due to Micrsoft Virtual Machine allowing Java applet to call JDBC API. By hosting a specially crafted Java applet or sending it to clients, a remote attacker can add, modify and delete the data in database with the user's priviledges, resulting in a loss of integrity. |
7886 | Microsoft Java Virtual Machine StandardSecurityManager Restriction Bypass |
7885 | Microsoft Java Implementation Applet Tag DoS |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2002-11-28 | Name : Arbitrary code can be executed on the remote host through the VM. File : smb_nt_ms02-052.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:44:47 |
|