← All CVEs

CVE-2002-0421

medium · 5

IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr password changing programs in the /iisadmpwd directory, including (1) aexp2.htr, (2) aexp2b.htr, (3) aexp3.htr , or (4) aexp4.htr.

5
CVSS
20.0%
EPSS (exploit prob.)
97th
EPSS percentile
2002-08-12
Published

AV:N/AC:L/Au:N/C:N/I:P/A:N

Affected products

VendorProductAffected versions
microsoftwindows_nt4.0
microsoftwindows_nt4.0
microsoftwindows_nt4.0
microsoftwindows_nt4.0
microsoftwindows_nt4.0
microsoftwindows_nt4.0
microsoftwindows_nt4.0
microsoftwindows_nt4.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2002-0421