CVE-2002-2401Microsoft Windows NT vulnerability

CWE-2643 documents3 sources
Severity
3.6LOWNVD
EPSS
0.2%
top 58.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 31
Latest updateApr 30

Description

NT Virtual DOS Machine (NTVDM.EXE) in Windows 2000, NT and XP does not verify user execution permissions for 16-bit executable files, which allows local users to bypass the loader and execute arbitrary programs.

CVSS vector

AV:L/AC:L/C:P/I:P/A:NExploitability: 3.9 | Impact: 4.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-h4w5-cff9-3fv9: NT Virtual DOS Machine (NTVDM2022-04-30
CVEList
CVE-2002-2401: NT Virtual DOS Machine (NTVDM2007-11-01