VULNERABILITY INTELLIGENCE
CVE-2002-2028
CVSS score2.1 LOW
EPSS probability1.97%
CISA KEVNot currently listed
Published2002-12-31
Last modified2026-06-16
CVSS vectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Description
The screensaver on Windows NT 4.0, 2000, XP, and 2002 does not verify if a domain account has already been locked when a valid password is provided, which makes it easier for users with physical access to conduct brute force password guessing.