Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2002-1230 | First vendor Publication | 2002-11-04 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 4.6 | Attack Range | Local |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code as LocalSystem via "shatter" style attack by sending a WM_COPYDATA message followed by a WM_TIMER message, as demonstrated by GetAd, aka "Flaw in Windows WM_TIMER Message Handling Could Enable Privilege Elevation." |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1230 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:681 | |||
Oval ID: | oval:org.mitre.oval:def:681 | ||
Title: | Flaw in Windows WM_TIMER Message Handling Could Enable Privilege Elevation | ||
Description: | NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code as LocalSystem via "shatter" style attack by sending a WM_COPYDATA message followed by a WM_TIMER message, as demonstrated by GetAd, aka "Flaw in Windows WM_TIMER Message Handling Could Enable Privilege Elevation." | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2002-1230 | Version: | 3 |
Platform(s): | Microsoft Windows NT | Product(s): | NetDDE Agent |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Os | 4 | |
Os | 4 |
OpenVAS Exploits
Date | Description |
---|---|
2009-03-15 | Name : MS04-011 security check File : nvt/remote-MS04-011.nasl |
2005-11-03 | Name : WM_TIMER Message Handler Privilege Elevation (Q328310) File : nvt/smb_nt_ms02-071.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
13416 | Microsoft Windows NetDDE Agent WM_COPYDATA Message Arbitrary Code Execution (... The Microsoft Windows NetDDE Agent in Windows 2000, NT, and XP contains a vulnerability that could allow a local attacker to elevate their privileges. An attacker could exploit this by sending specially crafted input to the NetDDE Agent via a WM_COPYDATA message, and then sending specially crafted input via WM_TIMER message, causing the request to be executed under higher privileges. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2002-12-12 | Name : Local users can elevate their privileges on the remote host. File : smb_nt_ms02-071.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:23:45 |
|
2024-11-28 12:05:13 |
|
2021-05-04 12:01:46 |
|
2021-04-22 01:01:54 |
|
2020-05-23 00:15:06 |
|
2019-04-30 21:19:17 |
|
2018-10-13 00:22:26 |
|
2017-10-10 09:23:24 |
|
2016-08-31 12:00:43 |
|
2016-06-28 15:00:23 |
|
2016-04-26 12:16:46 |
|
2014-02-17 10:25:12 |
|
2013-05-11 12:12:09 |
|