CVE-2002-0862

Microsoft Windows and Office - Improper Certificate Validation in CryptoAPI

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-0862.

AI-analyzed exploit summary The document describes a vulnerability in X.509 certificate handling, where intermediate certificates lacking the Basic Constraints field are improperly trusted. This allows attackers to spoof domains or perform man-in-the-middle attacks, affecting browsers like Internet Explorer and Konqueror, as well as IIS 5.0.

Description

The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.

Exploits (1)

exploitdb WRITEUP
remotewindows
https://www.exploit-db.com/exploits/21692

The document describes a vulnerability in X.509 certificate handling, where intermediate certificates lacking the Basic Constraints field are improperly trusted. This allows attackers to spoof domains or perform man-in-the-middle attacks, affecting browsers like Internet Explorer and Konqueror, as well as IIS 5.0.

Classification
Writeup 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Microsoft Internet Explorer, IIS 5.0, KDE/Konqueror (versions 3.0.2 and earlier)
No auth needed
Prerequisites: A valid certificate to sign a new certificate for an arbitrary domain
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (8)

Core 8
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=102918200405308&w=2
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=102866120821995&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/9776
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=102976967730450&w=2
Patch, Vendor Advisory vendor-advisory x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-050

Scores

EPSS 0.1867
EPSS Percentile 96.9%

Details

CWE
CWE-295
Status published
Products (9)
microsoft/internet_explorer
microsoft/office
microsoft/outlook_express
microsoft/windows_2000
microsoft/windows_98
microsoft/windows_98se
microsoft/windows_me
microsoft/windows_nt 4.0 (2 CPE variants)
microsoft/windows_xp
Published Oct 04, 2002
Tracked Since Feb 18, 2026