Vulnerability CVE-2002-0971


Published: 2002-09-24   Modified: 2012-02-12

Description:
Vulnerability in VNC, TightVNC, and TridiaVNC allows local users to execute arbitrary code as LocalSystem by using the Win32 Messaging System to bypass the VNC GUI and access the "Add new clients" dialogue box.

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.6/10
6.4/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Tridia -> Tridiavnc 
Tightvnc -> Tightvnc 
ATT -> Winvnc server 

 References:
http://marc.info/?l=bugtraq&m=102994289123085&w=2
http://www.iss.net/security_center/static/9979.php
http://www.securityfocus.com/bid/5530

Copyright 2024, cxsecurity.com

 

Back to Top