Back
CVE-2002-1824
Microsoft Internet Explorer 6.0, when handling an expired CA-CERT in a webserver's certificate chain during a SSL/TLS handshake, does not prompt the user before searching for and finding a newer certificate, which may allow attackers to perform a man-in-the-middle attack. NOTE: it is not clear whether this poses a vulnerability.
Published: Dec 31, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| microsoft | ie | 6.0 |
| microsoft | internet_explorer | 6.0 |
GitHub Security Advisory GHSA-rf6c-qmjq-7g7g
Microsoft Internet Explorer 6.0, when handling an expired CA-CERT in a webserver's certificate...
Risk Scores
CVSS Score
5.0 / 10
EPSS Score
2.58%
Top 16% most likely to be exploited
Threat Score
20.8 / 100
Data Sources
NVD
EPSS
GitHub