CVE-2002-0694
Estado: ModificadaAlta (7.5)—
The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed, aka "Code Execution via Compiled HTML Help File."
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 14%
- Percentil entre todas las CVEs puntuadas: 96
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (7)
CWE
- NVD-CWE-Other
Referencias
- http://www.iss.net/security_center/static/10254.php
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-055
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A403
- http://www.iss.net/security_center/static/10254.php
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-055
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A403
JSON original (NVD)
Mostrar
{
"id": "CVE-2002-0694",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2002-10-10T04:00:00.000",
"references": [
{
"url": "http://www.iss.net/security_center/static/10254.php",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-055",
"source": "cve@mitre.org"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A403",
"source": "cve@mitre.org"
},
{
"url": "http://www.iss.net/security_center/static/10254.php",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-055",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A403",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The HTML Help facility in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP uses the Local Computer Security Zone when opening .chm files from the Temporary Internet Files folder, which allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed, aka \"Code Execution via Compiled HTML Help File.\""
}
],
"lastModified": "2026-06-16T21:57:57.500",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_2000:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4E545C63-FE9C-4CA1-AF0F-D999D84D2AFD"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "294EBA01-147B-4DA0-937E-ACBB655EDE53"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4E8B7346-F2AA-434C-A048-7463EC1BB117"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE1A6107-DE00-4A1C-87FC-9E4015165B5B"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_2000_terminal_services:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9D34EFE5-22B7-4E8D-B5B2-2423C37CFFA7"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_2000_terminal_services:*:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8208AFC9-0EFC-4A90-AD5A-FD94F5542885"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_2000_terminal_services:*:sp2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D4168AE-D19E-482E-8F2B-3E798B2D84E7"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_2000_terminal_services:*:sp3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B5E149E7-B748-44F6-BB55-68D5BF87AF41"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_98:*:gold:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2D3B703C-79B2-4FA2-9E12-713AB977A880"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_98se:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AA733AD2-D948-46A0-A063-D29081A56F1F"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_me:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "799DA395-C7F8-477C-8BC7-5B4B88FB7503"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:*:enterprise_server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "237D7C18-C8D6-4FDB-A160-FA17DD46A55A"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:*:server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7C5FCE82-1E2F-49B9-B504-8C03F2BCF296"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:*:terminal_server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6E7E6AD3-5418-4FEA-84B5-833059CA880D"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:*:workstation:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "35346A7B-2CB5-446D-B0C3-1F21D71A746D"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp1:enterprise_server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "064F4E76-1B89-4FA5-97ED-64624285C014"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp1:server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "089A953C-8446-4E6F-B506-430C38DF37B1"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp1:terminal_server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EA262C44-C0E6-493A-B8E5-4D26E4013226"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp1:workstation:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "416F06DD-980E-4A54-822D-CBA499FD1F86"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp2:enterprise_server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F66DC6FF-2B3D-4718-838F-9E055E89961F"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp2:server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "656AE014-AEEC-46E8-A696-61FEA7932F21"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp2:terminal_server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EB519FE0-9E7D-4E71-8873-356C9D7CEAB5"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp2:workstation:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A08D0EA1-DA1B-4C52-883A-3F156F032517"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp3:enterprise_server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DA267420-56C5-4697-B0AA-52932F78B24B"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp3:server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "93BA426E-DD51-44AC-BE78-3164670FF9E1"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp3:terminal_server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "224F8968-9F4C-4727-AAA3-61F5578EF54C"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp3:workstation:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "02BE9817-E1AE-4619-8302-CA7AA4167F48"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp4:enterprise_server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "363E3895-A19B-42EC-B479-765168DC0B17"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp4:server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FBBBF25A-709B-4716-9894-AD82180091AD"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp4:terminal_server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "407DA6E8-0832-49FE-AE14-35C104C237EC"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp4:workstation:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "88B70B7A-5BCC-4626-AAC7-D1ACFF25D66E"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp5:enterprise_server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "81B7961D-151D-4773-80CB-CCD0456BFEAA"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp5:server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "82781A72-A34F-4668-9EE8-C203B04E3367"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp5:terminal_server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AFE612D2-DF38-404F-AED1-B8C9C24012DE"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp5:workstation:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "12ED7363-6EEE-4688-A9B7-C5EB1107A7B4"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp6:enterprise_server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B5CAF64E-98AA-4813-A2A2-5AC3387CF230"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp6:server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BCDFDBBA-6C4F-472A-9F4F-461C424794E7"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp6:terminal_server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BCC5E316-FB61-408B-BAA2-7FE03D581250"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp6:workstation:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EDDD8DA8-D074-4543-AEDF-F856B5567F21"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:enterprise_server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CA7BA525-6DB8-4444-934A-932AFED69816"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "90CFA69B-7814-4F97-A14D-D76310065CF3"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:terminal_server:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2FECD4B0-23A0-4C0B-9888-D28A5941D848"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_nt:4.0:sp6a:workstation:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AB6ADBAF-6EB0-4CFA-9D33-A814AC20484E"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_xp:*:*:home:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BC176BB0-1655-4BEA-A841-C4158167CC9B"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_xp:*:gold:professional:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4BF263CB-4239-4DB0-867C-9069ED02CAD7"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_xp:*:sp1:home:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "49693FA0-BF34-438B-AFF2-75ACC8A6D2E6"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}