CVE-2002-1932

Windows 2000 and XP - Log Overflow Detection Bypass via Event Log Configuration

Title source: llm
STIX 2.1

Description

Microsoft Windows XP and Windows 2000, when configured to send administrative alerts and the "Do not overwrite events (clear log manually)" option is set, does not notify the administrator when the log reaches its maximum size, which allows local users and remote attackers to avoid detection.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://online.securityfocus.com/archive/1/295341
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5972
Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3B329350

Scores

EPSS 0.1278
EPSS Percentile 95.9%

Details

Status published
Products (2)
microsoft/windows_2000 (3 CPE variants)
microsoft/windows_xp (2 CPE variants)
Published Dec 31, 2002
Tracked Since Feb 18, 2026