← Back

CVE-2002-0862

nvd nist
Published: Oct 4, 2002Modified: Apr 16, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.

Affected (10)

9 products
Windows 2000
Windows 98
Windows 98se
Windows Me
Windows Nt
Windows Xp
Internet Explorer
Office
Outlook Express
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
All versions
Microsoft
Version 4.0
Version 4.0
All versions
Configuration B
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
Running on/withPlatform Versions
Apple
Macos
All versions

References (16)

Source: cve@mitre.org
Mailing List
Source: cve@mitre.org
Mailing List
Source: cve@mitre.org
Mailing List
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.