Back
CVE-2002-1325
Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a local user's username via a Java applet that accesses the user.dir system property, aka "User.dir Exposure Vulnerability."
Published: Dec 23, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (43)
| Vendor | Product | Version |
|---|---|---|
| microsoft | windows_2000 | * |
| microsoft | windows_2000 | * |
| microsoft | windows_2000 | * |
| microsoft | windows_2000 | * |
| microsoft | windows_2000_terminal_services | * |
| microsoft | windows_2000_terminal_services | * |
| microsoft | windows_2000_terminal_services | * |
| microsoft | windows_2000_terminal_services | * |
| microsoft | windows_95 | * |
| microsoft | windows_95 | * |
| microsoft | windows_98 | * |
| microsoft | windows_98se | * |
| microsoft | windows_me | * |
| microsoft | windows_nt | 4.0 |
| microsoft | windows_nt | 4.0 |
| microsoft | windows_nt | 4.0 |
| microsoft | windows_nt | 4.0 |
| microsoft | windows_nt | 4.0 |
| microsoft | windows_nt | 4.0 |
| microsoft | windows_nt | 4.0 |
…and 23 more
GitHub Security Advisory GHSA-f83w-r37q-vphp
Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a...
Risk Scores
CVSS Score
5.0 / 10
EPSS Score
13.86%
Top 4% most likely to be exploited
Threat Score
24.2 / 100
Data Sources
NVD
EPSS
GitHub