CVE-2002-0736

CRITICAL

Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request wit...

Affects 1 product across 1 vendor.

BCS7.9
CVSS 2.010.0
EPSS31.6%
Percentile98th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2002. A critical vulnerability affects Microsoft systems (CVE-2002-0736). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2002-GLOBAL-351066-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2002-0736?
This vulnerability was disclosed in 2002. A critical vulnerability affects Microsoft systems (CVE-2002-0736). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2002-0736?
CVE-2002-0736 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 31.6%.
Is CVE-2002-0736 actively exploited?
No confirmed active exploitation of CVE-2002-0736 as of 2026-05-30.
How do I remediate CVE-2002-0736?
Priority: MEDIUM. Advisory: http://support.microsoft.com/support/kb/articles/q316/8/38.asp PSIRT: [email protected]
What systems are affected by CVE-2002-0736?
CVE-2002-0736 affects: Microsoft.
Vulnerability Details
CVE IDCVE-2002-0736
BSIDBS-2002-GLOBAL-351066-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2002-08-12
Last Modified2026-04-16
ICS Relevance0%
SourceNVD
Official Description

Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with an authorization type (auth_type) that is not blank.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with an authorization type (auth_type) that is not blank. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Microsoft Backoffice
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 8757 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash2dd1a8e24a39da0a5a9fd4992b5daeb8c0b3ff24005768455f89d2793d2aaf8fcfafb44963d2961689bc2c79d3b15af94d3f3a4cdc81e952a80a26c8f616ee76
Related CVEs affecting Microsoft
CVE-2003-0528 10.0 Heap-based buffer overflow in the Distributed Component Object Model (DCOM) i... CVE-2000-0788 10.0 The Mail Merge tool in Microsoft Word does not prompt the user before executi... CVE-2000-1034 10.0 Buffer overflow in the System Monitor ActiveX control in Windows 2000 allows ... CVE-2001-0045 10.0 The default permissions for the RAS Administration key in Windows NT 4.0 allo... CVE-2001-0147 10.0 Buffer overflow in Windows 2000 event viewer snap-in allows attackers to exec...
View all Microsoft CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →