CVE-2002-0421
IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr password changing programs in the /iisadmpwd directory, including (1) aexp2.htr, (2) aexp2b.htr, (3) aexp3.htr , or (4) aexp4.htr.
Scoring
- CVSS base score
- 0.95
- EPSS probability
- 23.70%
- Published
- 2002-06-11
- Last modified
- 2026-03-16
Affected products
- n/a n/a