LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2002-0862

CVE-2002-0862

CVSS 6.8 · MEDIUM

Summary

The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.

CVSS 2.0 breakdown

Base score6.8 (MEDIUM)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Attack vectorNETWORK
Attack complexityMEDIUM
ConfidentialityPARTIAL
IntegrityPARTIAL
AvailabilityPARTIAL

Weakness type (CWE)

Affected products

Microsoft windows 2000Microsoft windows 98Microsoft windows 98seMicrosoft windows meMicrosoft windows ntMicrosoft windows xpMicrosoft internet explorerMicrosoft officeMicrosoft outlook expressApple macos
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD. NVD last modified 2026-04-16. Always verify against the vendor advisory before acting.

Scroll to Top