CVE-2002-2324

Windows XP - Unprotected User Data Exposure via System Restore Directory ACL

Title source: llm
STIX 2.1

Description

The "System Restore" directory and subdirectories, and possibly other subdirectories in the "System Volume Information" directory on Windows XP Professional, have insecure access control list (ACL) permissions, which allows local users to access restricted files and modify registry settings.

References (3)

Core 3
Core References
Exploit mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-10/0070.html
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10279.php
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5894

Scores

EPSS 0.0177
EPSS Percentile 76.0%

Details

CWE
CWE-264
Status published
Products (1)
microsoft/windows_xp
Published Dec 31, 2002
Tracked Since Feb 18, 2026