Description
The DCOM client in Windows 2000 before SP3 does not properly clear memory before sending an "alter context" request, which may allow remote attackers to obtain sensitive information by sniffing the session.
References (4)
Core 4
Core References
Patch vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/4410
Patch, Vendor Advisory vendor-advisory
x_refsource_bindview
http://www.bindview.com/Services/razor/Advisories/2002/adv_dcom.cfm
Vendor Advisory vendor-advisory
x_refsource_mskb
http://support.microsoft.com/default.aspx?scid=kb%3BEN-US%3Bq300367
Patch vdb-entry
x_refsource_xf
http://www.iss.net/security_center/static/8739.php
Scores
EPSS
0.1587
EPSS Percentile
96.6%
Details
Status
published
Products (1)
microsoft/windows_2000
(3 CPE variants)
Published
Dec 31, 2002
Tracked Since
Feb 18, 2026