Description
The system root folder of Microsoft Windows 2000 has default permissions of Everyone group with Full access (Everyone:F) and is in the search path when locating programs during login or application launch from the desktop, which could allow attackers to gain privileges as other users via Trojan horse programs.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/5415
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-064
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/9779
Scores
EPSS
0.0190
EPSS Percentile
77.7%
Details
Status
published
Products (2)
microsoft/windows_2000
(4 CPE variants)
microsoft/windows_nt
4.0 (24 CPE variants)
Published
Nov 12, 2002
Tracked Since
Feb 18, 2026