CVE-2002-1694
Description
Microsoft Internet Information Server (IIS) 4.0 opens log files with FILE_SHARE_READ and FILE_SHARE_WRITE permissions, which could allow remote attackers to modify the log file contents while IIS is running.
In plain language
AI Worth attentionCVE-2002-1694 is a Microsoft IIS 4.0 issue where remote attackers can tamper with log file contents while the server is running; if you’re still using IIS 4.0, you should treat this as a real concern and update/mitigate.
In Microsoft Internet Information Services (IIS) 4.0, log files are opened with overly permissive sharing (read/write sharing), allowing unauthenticated remote attackers to modify log contents during normal server operation.
What to do now
- Check whether you are running “Microsoft Internet Information Services (IIS) 4.0” on any server (including legacy/edge systems).
- If IIS 4.0 is in use, plan an upgrade or migration to a supported IIS version immediately; no fixed patch version is identified for CVE-2002-1694.
- If you cannot upgrade right away, limit exposure by ensuring IIS is not reachable directly from the internet and restrict who can access the server and its log files.
- Review and harden logging/alerting: validate that log files are protected from modification by unauthorized users and monitor for signs of log changes or unusual requests.
CVSS Vector Breakdown
AV:NAccess VectorAC:LAccess ComplexityAu:NAuthenticationC:NConfidentialityI:PIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2002-1694 and every CVE in our database. Create a free account — no credit card required.
Create Free Account