CVE-2002-2401

Windows NT and 2000 - Unauthenticated Arbitrary Program Execution via NTVDM.EXE

Title source: llm
STIX 2.1

Description

NT Virtual DOS Machine (NTVDM.EXE) in Windows 2000, NT and XP does not verify user execution permissions for 16-bit executable files, which allows local users to bypass the loader and execute arbitrary programs.

References (5)

Core 5
Core References
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10132.php
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-09/0211.html
Various Sources x_refsource_misc
http://www.abtrusion.com/msexe16.asp
Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/default.aspx?scid=kb%3B%5BLN%5D%3B319458
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5740

Scores

EPSS 0.0181
EPSS Percentile 76.5%

Details

CWE
CWE-264
Status published
Products (3)
microsoft/windows_2000 (4 CPE variants)
microsoft/windows_nt 4.0 (29 CPE variants)
microsoft/windows_xp (4 CPE variants)
Published Dec 31, 2002
Tracked Since Feb 18, 2026