← All CVEs

CVE-2002-0862

medium · 6.8

The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.

6.8
CVSS
15.8%
EPSS (exploit prob.)
97th
EPSS percentile
2002-10-04
Published

AV:N/AC:M/Au:N/C:P/I:P/A:P

Weaknesses

CWE-295

Affected products

VendorProductAffected versions
microsoftwindows_2000all versions
microsoftwindows_98all versions
microsoftwindows_98seall versions
microsoftwindows_meall versions
microsoftwindows_nt4.0
microsoftwindows_nt4.0
microsoftwindows_xpall versions
microsoftinternet_explorerall versions
microsoftofficeall versions
microsoftoutlook_expressall versions
applemacosall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2002-0862