PUBLISHED DATE: July 3, 2002CVE-2002-0366: Buffer Overflow Vulnerability
CVSS:
7.2
EPSS:
49.70%
Exploitability:
3.9
In KEV:
No
Description
Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.
Products
Microsoft Windows 2000
Microsoft Windows 2000 Service Pack 1
Microsoft Windows 2000 Service Pack 2
Microsoft Windows 2000
Microsoft Windows 2000 Japanese Server Edition
Microsoft Windows 2000 Advanced Server Edition
Microsoft Windows 2000 Datacenter Server Edition
Microsoft Windows 2000 Professional Edition
Microsoft Windows 2000 Server Edition
Microsoft Windows 2000 Beta 3
Microsoft windows 2000_gold
Microsoft Windows 2000 Addvanced Server (Initial Release)
Microsoft Windows 2000 Datacenter Server (Initial Release)
Microsoft Windows 2000 Professional (Initial release)
Microsoft Windows 2000 Server (Inital release)
Microsoft windows 2000_rc1
Microsoft windows 2000_rc2
Microsoft windows 2000_sp1
Microsoft Windows 2000 Service Pack 1 Advanced Server Edition
Microsoft Windows 2000 Service Pack 1 Datacenter Server Edition
Microsoft Windows 2000 Service Pack 1 Professional Edition
Microsoft Windows 2000 Service Pack 1 Server Edition
Microsoft Windows 2000 Advanced Server SP1
Microsoft Windows 2000 Datacenter Server SP1
Microsoft Windows 2000 Professional SP1
Microsoft Windows 2000 Server SP1
Microsoft windows 2000_sp2
Microsoft Windows 2000 Service Pack 2 Advanced Server Edition
Microsoft Windows 2000 Service Pack 2 Datacenter Server Edition
Microsoft Windows 2000 Service Pack 2 Professional Edition
Microsoft Windows 2000 Service Pack 2 Server Edition
Microsoft Windows 2000 Advanced Server SP2
Microsoft Windows 2000 Datacenter Server SP2
Microsoft Windows 2000 Professional SP2
Microsoft Windows 2000 Server SP2
Microsoft windows 2000_sp3
Microsoft Windows 2000 Service Pack 3 Advanced Server Edition
Microsoft Windows 2000 Service Pack 3 Datacenter Server Edition
Microsoft Windows 2000 Service Pack 3 Professional Edition
Microsoft Windows 2000 Service Pack 3 Server Edition
Microsoft Windows 2000 Advanced Server SP3
Microsoft Windows 2000 Datacenter Server SP3
Microsoft Windows 2000 Professional SP3
Microsoft Windows 2000 Server SP3
Microsoft Windows 2000 Service Pack 4
Microsoft Windows 2000 Service Pack 4 Advanced Server Edition
Microsoft Windows 2000 Service Pack 4 Datacenter Server Edition
Microsoft Windows 2000 Service Pack 4 Professional Edition
Microsoft Windows 2000 Service Pack 4 Server Edition
Microsoft Windows 2000 Service Pack 4 French
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows 2000 Datacenter Server SP4
Microsoft Windows 2000 Professional SP4
Microsoft Windows 2000 Server SP4
Microsoft windows 2000_beta3
Microsoft Windows NT 4.0 Enterprise Server
Microsoft Windows NT 4.0 Server
Microsoft Windows NT 4.0 Terminal Server
Microsoft Windows NT 4.0 Workstation
Microsoft Windows 4.0 gold server
Microsoft Windows NT 4.0 Terminal Server Edition (Initial release)
Microsoft Windows 4.0 gold workstation
Microsoft Windows NT 4.0 Service Pack 1 Enterprise Server
Microsoft Windows 4.0 sp1 server
Microsoft Windows NT Terminal Server 4.0 SP1
Microsoft Windows 4.0 sp1 workstation
Microsoft Windows NT 4.0 Service Pack 2 Enterprise Server
Microsoft Windows 4.0 sp2 server
Microsoft Windows NT Terminal Server 4.0 SP2
Microsoft Windows 4.0 sp2 workstation
Microsoft Windows NT 4.0 Service Pack 3 Enterprise Server
Microsoft Windows 4.0 sp3 server
Microsoft Windows NT Terminal Server 4.0 SP3
Microsoft Windows 4.0 sp3 workstation
Microsoft Windows NT 4.0 Service Pack 4 Enterprise Server
Microsoft Windows 4.0 sp4 server
Microsoft Windows NT Terminal Server 4.0 SP4
Microsoft Windows 4.0 sp4 workstation
Microsoft Windows NT 4.0 Service Pack 5 Enterprise Server
Microsoft Windows 4.0 sp5 server
Microsoft Windows NT Terminal Server 4.0 SP5
Microsoft Windows 4.0 sp5 workstation
Microsoft Windows NT 4.0 Service Pack 6 Enterprise Server
Microsoft Windows 4.0 sp6 server
Microsoft Windows NT Terminal Server 4.0 SP6
Microsoft Windows 4.0 sp6 workstation
Microsoft Windows NT 4.0 Service Pack 6a Enterprise Server
Microsoft Windows 4.0 sp6a server
Microsoft Windows NT Terminal Server 4.0 SP6a
Microsoft Windows 4.0 sp6a workstation
Microsoft Windows NT 4.0 Server Post Service Pack 6a Security Rollup
Microsoft Windows NT 4.0 Service Roll-up Terminal Server
Microsoft Windows NT 4.0 Workstation Post Service Pack 6a Security Rollup
Microsoft Windows XP 64-bit
Microsoft Windows XP Home Edition
Microsoft Windows XP Gold Professional
Microsoft Windows XP (gold) Home Edition
Microsoft Windows XP Professional Gold
Microsoft Windows XP Service Pack 1 Home Edition
Microsoft Windows XP Service Pack 2 Home Edition
Microsoft Windows XP Service Pack 3 Home Edition
Questions to Ask Vendors
Can you confirm whether your systems are affected by CVE-2002-0366, and if so, what steps are you currently taking to mitigate this vulnerability?
What is your estimated timeline for fully resolving CVE-2002-0366 in your products or services, and how will you communicate updates on this issue to us as your customer?