peter bassill · operator
$ cve CVE-2002-0862 JSON

CVE-2002-0862 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 15.8% (pctl 97)

Patch early

A public exploit exists.

Description

The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS15.76% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-295
On CISA KEVno
Public exploityes
Published2002-10-04
Last modified2026-06-16

Affected (10)

VendorProduct
applemacos
microsoftinternet explorer
microsoftoffice
microsoftoutlook express
microsoftwindows 2000
microsoftwindows 98
microsoftwindows 98se
microsoftwindows me
microsoftwindows nt
microsoftwindows xp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD