CVE-2002-2401 — Microsoft Windows NT vulnerability
Severity
3.6LOWNVD
EPSS
0.2%
top 58.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 31
Latest updateApr 30
Description
NT Virtual DOS Machine (NTVDM.EXE) in Windows 2000, NT and XP does not verify user execution permissions for 16-bit executable files, which allows local users to bypass the loader and execute arbitrary programs.
CVSS vector
AV:L/AC:L/C:P/I:P/A:NExploitability: 3.9 | Impact: 4.9