CVE-2002-0472

critical

Description

MSN Messenger Service 3.6, and possibly other versions, uses weak authentication when exchanging messages between clients, which allows remote attackers to spoof messages from other users.

References

http://www.securityfocus.com/bid/4316

http://www.securityfocus.com/archive/1/262906

http://www.iss.net/security_center/static/8582.php

http://www.encode-sec.com/esp0202.pdf

Details

Source: Mitre, NVD

Published: 2002-08-12

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical

EPSS

EPSS: 0.14531