CVE-2002-1932
Windows 2000 and XP - Log Overflow Detection Bypass via Event Log Configuration
Title source: llmDescription
Microsoft Windows XP and Windows 2000, when configured to send administrative alerts and the "Do not overwrite events (clear log manually)" option is set, does not notify the administrator when the log reaches its maximum size, which allows local users and remote attackers to avoid detection.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://online.securityfocus.com/archive/1/295341
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/5972
Vendor Advisory vendor-advisory
x_refsource_mskb
http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3B329350
Patch vdb-entry
x_refsource_xf
http://www.iss.net/security_center/static/10377.php
Scores
EPSS
0.1278
EPSS Percentile
95.9%
Details
Status
published
Products (2)
microsoft/windows_2000
(3 CPE variants)
microsoft/windows_xp
(2 CPE variants)
Published
Dec 31, 2002
Tracked Since
Feb 18, 2026