CVE-2002-0049

Microsoft Exchange Server 2000 - Improper Privilege Management in WinReg Key

Title source: llm
STIX 2.1

Description

Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/8092
Patch, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4053
Broken Link vdb-entry x_refsource_osvdb
http://www.osvdb.org/2042
Patch, Vendor Advisory vendor-advisory x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-003

Scores

EPSS 0.1331
EPSS Percentile 95.9%

Details

CWE
CWE-269
Status published
Products (1)
microsoft/exchange_server 2000
Published Mar 08, 2002
Tracked Since Feb 18, 2026