Back
CVE-2002-0869
Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of Process Privilege Elevation."
Published: Nov 12, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| microsoft | internet_information_server | 4.0 |
| microsoft | internet_information_services | 5.0 |
GitHub Security Advisory GHSA-vcf2-r78h-5vfw
Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information...
References (18)
- http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0059.html
- http://marc.info/?l=bugtraq&m=103642839205574&w=2
- http://www.ciac.org/ciac/bulletins/n-011.shtml
- http://www.iss.net/security_center/static/10502.php Patch, Vendor Advisory
- http://www.li0n.pe.kr/eng/advisory/ms/iis_impersonation.txt
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-062
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A929
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A930
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A983
- http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0059.html
- http://marc.info/?l=bugtraq&m=103642839205574&w=2
- http://www.ciac.org/ciac/bulletins/n-011.shtml
- http://www.iss.net/security_center/static/10502.php Patch, Vendor Advisory
- http://www.li0n.pe.kr/eng/advisory/ms/iis_impersonation.txt
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-062
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
21.57%
Top 3% most likely to be exploited
Threat Score
36.5 / 100
Data Sources
NVD
EPSS
GitHub