CVE-2002-2077

Windows 2000 <SP3 - Info Disclosure

Title source: llm
STIX 2.1

Description

The DCOM client in Windows 2000 before SP3 does not properly clear memory before sending an "alter context" request, which may allow remote attackers to obtain sensitive information by sniffing the session.

References (4)

Core 4
Core References
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4410
Patch, Vendor Advisory vendor-advisory x_refsource_bindview
http://www.bindview.com/Services/razor/Advisories/2002/adv_dcom.cfm
Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/default.aspx?scid=kb%3BEN-US%3Bq300367

Scores

EPSS 0.1587
EPSS Percentile 96.6%

Details

Status published
Products (1)
microsoft/windows_2000 (3 CPE variants)
Published Dec 31, 2002
Tracked Since Feb 18, 2026