The DCOM client in Windows 2000 before SP3 does not properly clear memory before sending an "alter context" request, which may allow remote attackers to obtain sensitive information by sniffing the session.
References
Link | Resource |
---|---|
http://www.bindview.com/Services/razor/Advisories/2002/adv_dcom.cfm | Patch Vendor Advisory |
http://support.microsoft.com/default.aspx?scid=kb;EN-US;q300367 | Patch |
http://www.securityfocus.com/bid/4410 | Patch |
http://www.iss.net/security_center/static/8739.php | Patch |
Configurations
Configuration 1 (hide)
|
Information
Published : 2002-12-30 21:00
Updated : 2019-04-30 07:27
NVD link : CVE-2002-2077
Mitre link : CVE-2002-2077
JSON object : View
CWE
Products Affected
microsoft
- windows_2000