<?xml version="1.0" encoding="UTF-8"?>
<oval xmlns="http://oval.mitre.org/XMLSchema/oval" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:oval="http://oval.mitre.org/XMLSchema/oval" xmlns:windows="http://oval.mitre.org/XMLSchema/oval#windows" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval oval-schema.xsd http://oval.mitre.org/XMLSchema/oval#windows windows-schema.xsd">
	<generator>
		<schema_version>4</schema_version>
		<timestamp>20050803235300</timestamp>
	</generator>
	<definitions>
		<definition id="OVAL3" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Exchange Server 2003</product>
			</affected>
			<dates>
				<submitted date="2005-06-06">
					<contributor organization="The MITRE Corporation">Charles Schmidt</contributor>
				</submitted>
				<status_change date="2005-06-08">DRAFT</status_change>
				<status_change date="2005-06-29">INTERIM</status_change>
				<status_change date="2005-07-27">ACCEPTED</status_change>
			</dates>
			<description>'The Exchange 2003 Exadmin virtual directory uses only Integrated Windows Authentication.'</description>
			<reference source="MISC">2.1.6</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<oval:notes>
				<oval:note>Corresponds to item 2.1.6 in the Exchange 2003 Benchmark</oval:note>
			</oval:notes>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-113" comment="Exchange Server 2003 (gold edition) is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wat-1" comment="The exadmin HTTP virtual directory only allows Integrated Windows Authentication" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL12" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
			</dates>
			<description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.</description>
			<reference source="CVE">CVE-2002-0026</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-201" comment="the version of mshtml.dll is less than 5.50.4913.1100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL16" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code.</description>
			<reference source="CVE">CVE-2002-0079</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL17" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
			</dates>
			<description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
			<reference source="CVE">CVE-2002-0023</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-203" comment="the version of mshtml.dll is less than 6.0.2713.1100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL18" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<dates>
				<submitted date="2004-09-15">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</submitted>
				<modified date="2004-09-16" comment="Completing an initial submission.">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</modified>
				<status_change date="2004-09-29">DRAFT</status_change>
				<status_change date="2004-10-13">INTERIM</status_change>
				<modified date="2004-10-19" comment="done">
					<contributor organization="The MITRE Corporation">Matthew Burton</contributor>
				</modified>
				<status_change date="2004-10-27">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled.</description>
			<reference source="CVE">CVE-2002-0070</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-490" comment="the version of shell32.dll is less than 4.0.1381.7116" />
					<criterion test_ref="wrt-288" negate="true" comment="Patch Q313829 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL19" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
			</dates>
			<description>Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Computer zone via a URL that exploits a local HTML resource file, aka the &quot;Cross-Site Scripting in Local HTML Resource&quot; vulnerability.</description>
			<reference source="CVE">CAN-2002-0189</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-204" comment="the version of mshtml.dll is less than 6.0.2716.2200" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="cmp-212" negate="true" comment="Windows 2000 Service Pack 4 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL20" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Distributed Component Object Model (DCOM) interface</product>
			</affected>
			<dates>
				<submitted date="2004-11-02">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-11-03">DRAFT</status_change>
				<status_change date="2004-12-09">INTERIM</status_change>
				<status_change date="2005-01-06">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different vulnerability than CAN-2003-0352 (Blaster/Nachi) and CAN-2003-0528.</description>
			<reference source="CVE">CAN-2003-0715</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-568" comment="the version of rpcss.dll is less than 5.0.2195.6810" />
					<criterion test_ref="wrt-281" negate="true" comment="the patch kb824146 is installed (Hotfix key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL22" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka &quot;Microsoft-discovered variant of Chunked Encoding buffer overrun.&quot;</description>
			<reference source="CVE">CVE-2002-0147</reference>
			<status>ACCEPTED</status>
			<version>4</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL23" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5 or Internet Explorer 5.5 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
			</dates>
			<description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.</description>
			<reference source="CVE">CVE-2002-0026</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-213" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-206" comment="the version of mshtml.dll is less than 5.50.4725.2100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL24" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>FTP</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters.</description>
			<reference source="CVE">CVE-2002-0073</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-202" comment="FTP Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL25" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code.</description>
			<reference source="CVE">CVE-2002-0079</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL26" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Network Connection Manager (NCM)</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<modified date="2005-03-07" comment="modified wrt-222 - changed pattern match">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>A handler routine for the Network Connection Manager (NCM) in Windows 2000 allows local users to gain privileges via a complex attack that causes the handler to run in the LocalSystem context with user-specified code.</description>
			<reference source="CVE">CVE-2002-0720</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
					<criterion test_ref="wft-207" comment="the version of netman.dll is less than 5.0.2195.5974" />
					<criterion test_ref="wrt-229" negate="true" comment="Patch Q326886 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL27" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.01</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2005-03-07" comment="modified wrt-222 - changed pattern match">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the &quot;Content Disposition&quot; vulnerability.</description>
			<reference source="CVE">CVE-2002-0193</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-214" comment="Internet Explorer 5.01 Installed" />
					<criterion test_ref="wft-208" comment="the version of mshtml.dll is less than 5.0.3504.2500" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="cmp-215" negate="true" comment="Windows 2000 Service Pack 4 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL29" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka &quot;Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise.&quot;</description>
			<reference source="CVE">CVE-2002-0364</reference>
			<status>ACCEPTED</status>
			<version>4</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-209" comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.5671" />
					<criterion test_ref="wrt-238" negate="true" comment="Patch Q321599 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-203" comment="ism.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL30" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SMTP</product>
			</affected>
			<dates>
				<submitted date="2003-05-20">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-03-30" comment="Changed the registry key in question for the SMTP enabled check to SMTPSVC from SMTP.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
			</dates>
			<description>SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 to cause a denial of service via a command with a malformed data transfer (BDAT) request.</description>
			<reference source="CVE">CVE-2002-0055</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-210" comment="File %windir%\system32\inetsrv\smtpsvc.dll version is less than 5.0.2195.4905" />
					<criterion test_ref="wrt-239" negate="true" comment="Patch Q313450" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-240" comment="SMTP Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL32" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
			</dates>
			<description>Internet Explorer 5.5 and 6.0 allows remote attackers to bypass restrictions for executing scripts via an object that processes asynchronous events after the initial security checks have been made.</description>
			<reference source="CVE">CVE-2002-0026</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-203" comment="the version of mshtml.dll is less than 6.0.2713.1100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL35" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>FTP</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters.</description>
			<reference source="CVE">CVE-2002-0073</reference>
			<status>ACCEPTED</status>
			<version>4</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-202" comment="FTP Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL37" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and &quot;\&quot; characters twice.</description>
			<reference source="CVE">CVE-2001-0333</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-211" comment="File %windir%\system32\inetsrv\ism.dll version is less than 4.2.764.1" />
					<criterion test_ref="wrt-241" negate="true" comment="Patch Q295534 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-243" negate="true" comment="Windows NT 4.0 Security Roll-up Package" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL38" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2003-05-13">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Windows 2000 allows local users to prevent the application of new group policy settings by opening Group Policy files with exclusive-read access.</description>
			<reference source="CVE">CVE-2002-0051</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-220" comment="Windows 2000 (domain controller) is installed" />
					<criterion test_ref="wft-212" comment="the version of srvsvc.dll is less than 5.00.2195.4980" />
					<criterion test_ref="wrt-246" negate="true" comment="Patch Q318593 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL39" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values.</description>
			<reference source="CVE">CVE-2002-0150</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL40" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
			</dates>
			<description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
			<reference source="CVE">CVE-2002-0023</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-53" comment="Internet Explorer 5.5 Service Pack 2 is installed" />
					<criterion test_ref="wft-201" comment="the version of mshtml.dll is less than 5.50.4913.1100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL44" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the &quot;Web Server Folder Traversal&quot; vulnerability.</description>
			<reference source="CVE">CVE-2000-0884</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-213" comment="File %windir%\system32\inetsrv\w3svc.dll version is less than 5.0.2195.2103" />
					<criterion test_ref="wrt-247" negate="true" comment="Patch Q269862 Installed" />
					<criterion test_ref="wrt-248" negate="true" comment="Patch Q277873 Installed" />
					<criterion test_ref="wrt-249" negate="true" comment="Patch Q293826 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-250" negate="true" comment="Win2K/XP/2003 service pack 2 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL45" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names.</description>
			<reference source="CVE">CVE-2002-0071</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-203" comment="ism.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL46" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to embed scripts into another user's session.</description>
			<reference source="CVE">CVE-2002-0074</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL49" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.01</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
			</dates>
			<description>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka &quot;Improper Cross Domain Security Validation with dialog box.&quot;</description>
			<reference source="CVE">CVE-2003-1326</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-230" comment="Internet Explorer 5.01 Installed" />
					<criterion test_ref="wft-214" comment="File %windir%\system32\mshtml.dll version is less than 5.0.3513.900" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-252" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL50" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.01, Internet Explorer 5.01 Service Pack 1, or Internet Explorer 5.01 Service Pack 2</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
			</dates>
			<description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
			<reference source="CVE">CVE-2002-0023</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-214" comment="Internet Explorer 5.01 Installed" />
					<criterion test_ref="wft-215" comment="the version of mshtml.dll is less than 5.0.3502.4856" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL57" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
			</dates>
			<description>The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka &quot;Improper Cross Domain Security Validation with ShowHelp functionality.&quot;</description>
			<reference source="CVE">CVE-2003-1328</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-216" comment="the version of mshtml.dll is less than 6.0.2723.2500" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL58" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<dates>
				<submitted date="2003-08-20">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (&quot;&quot;302 Object Moved&quot;) message.</description>
			<reference source="CVE">CVE-2002-0075</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL59" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2005-03-07" comment="modified wrt-222 - changed pattern match">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a malformed packet to the RPC Endpoint Mapper at TCP port 135, which triggers a null pointer dereference.</description>
			<reference source="CVE">CAN-2002-1561</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-217" comment="File %windir%\system32\rpcrt4.dll version is less than 5.0.2195.6106" />
					<criterion test_ref="wrt-253" negate="true" comment="Patch Q331953_W2K_SP4_X86_EN.exe Installed" />
					<criterion test_ref="wrt-254" negate="true" comment="Patch Windows2000-KB823980-x86-ENU.exe Installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL61" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Remote Access Service (RAS)</product>
			</affected>
			<dates>
				<submitted date="2003-04-04">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.</description>
			<reference source="CVE">CVE-2002-0366</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wrt-256" comment="RAS Phonebook" />
					<criterion test_ref="wft-218" comment="File %windir%\system32\rasapi32.dll version is less than 4.0.1381.7140" />
					<criterion test_ref="wrt-257" negate="true" comment="Patch Q318138 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-258" comment="RAS Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL63" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Access Service (RAS)</product>
			</affected>
			<dates>
				<submitted date="2003-04-04">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Buffer overflow in Remote Access Service (RAS) phonebook for Windows NT 4.0, 2000, XP, and Routing and Remote Access Server (RRAS) allows local users to execute arbitrary code by modifying the rasphone.pbk file to use a long dial-up entry.</description>
			<reference source="CVE">CVE-2002-0366</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wrt-256" comment="RAS Phonebook" />
					<criterion test_ref="wft-219" comment="File %windir%\system32\rasman.dll version is less than 5.0.2195.4983" />
					<criterion test_ref="wrt-257" negate="true" comment="Patch Q318138 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-258" comment="RAS Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL64" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2003-05-13">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-08-04" comment="Modifed without comment">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</modified>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<status_change date="2004-08-26">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which could allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain.</description>
			<reference source="CVE">CVE-2002-0018</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-220" comment="File %windir%\system32\netlogon.dll version is less than 5.00.0893.1105" />
					<criterion test_ref="wrt-259" negate="true" comment="Windows 2000 Security Roll-up 1 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL66" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
				<modified date="2005-03-07" comment="modified wrt-222 - changed pattern match">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>Cross-site scripting vulnerability (XSS) in the ASP function responsible for redirection in Microsoft Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to embed a URL containing script in a redirection message.</description>
			<reference source="CVE">CAN-2003-0223</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-221" comment="File %windir%\system32\inetsrv\asp.dll version is less than 5.0.2195.6672" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-222" negate="true" comment="SP4 or later Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL71" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft SQL Server 2000</product>
			</affected>
			<dates>
				<submitted date="2003-06-24">
					<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
				<modified date="2005-04-07" comment="modified wft-222 - corrected literal component of file path. It was missing the leading '\'">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</modified>
				<modified date="2005-04-07" comment="modified wft-222 - Corrected comment">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>An SQL query method in Microsoft SQL Server 2000 Gold and 7.0 using Mixed Mode allows local database users to gain privileges by reusing a cached connection of the sa administrator account.</description>
			<reference source="CVE">CVE-2001-0344</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-222" comment="the version of sqlservr.exe is less than 2000.80.296.0" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-261" comment="Mixed Mode Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL72" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka &quot;Microsoft-discovered variant of Chunked Encoding buffer overrun.&quot;</description>
			<reference source="CVE">CVE-2002-0147</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL76" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2003-04-04">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.</description>
			<reference source="CVE">CVE-2002-0367</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-223" comment="File %windir%\system32\smss.exe version is less than 5.0.2195.5695" />
					<criterion test_ref="wrt-262" negate="true" comment="Patch Q320206 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL77" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5 or Internet Explorer 5.5 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
			</dates>
			<description>Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.</description>
			<reference source="CVE">CVE-2002-0023</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-213" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-206" comment="the version of mshtml.dll is less than 5.50.4725.2100" />
					<criterion test_ref="wrt-202" negate="true" comment="the patch q316059 is installed (Installed Components key)" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL78" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-08-04" comment="Modifed without comment">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</modified>
				<status_change date="2004-08-25">ACCEPTED</status_change>
				<status_change date="2004-08-26">INTERIM</status_change>
				<status_change date="2004-09-09">ACCEPTED</status_change>
			</dates>
			<description>Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and &quot;\&quot; characters twice.</description>
			<reference source="CVE">CVE-2001-0333</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-224" comment="File %windir%\system32\inetsrv\ism.dll version is less than 5.0.2195.3407" />
					<criterion test_ref="wrt-249" negate="true" comment="Patch Q293826 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-259" negate="true" comment="Windows 2000 Security Roll-up 1 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL81" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<dates>
				<submitted date="2003-08-20">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page.</description>
			<reference source="CVE">CVE-2002-0148</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL82" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft SQL Server 2000</product>
			</affected>
			<dates>
				<submitted date="2003-08-27">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2005-04-07" comment="modified wft-225 - correct literal component in file path. Added '\' to the start of the literal string.">
					<contributor organization="The MITRE Corporation">Jonathan Baker</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<modified date="2005-04-12" comment="modified wft-89 - wft-89 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.</description>
			<reference source="CVE">CAN-2001-0509</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-225" comment="the version of ssmsrp70.dll is less than 2000.80.213.0" />
					<criterion test_ref="wft-59" comment="the version of dbmsrpcn.dll is less than 2000.80.213.0" />
					<criterion test_ref="wft-89" negate="true" comment="File sqlservr.exe version3 greater than or equal to 384" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL83" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft SQL Server</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
				</submitted>
				<modified date="2005-04-08" comment="modified wft-227 - corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflows in Microsoft SQL Server 7.0 and 2000 allow attackers with access to SQL Server to execute arbitrary code through the functions (1) raiserror, (2) formatmessage, or (3) xp_sprintf. NOTE: the C runtime format string vulnerability reported in MS01-060 is identified by CAN-2001-0879.</description>
			<reference source="CVE">CAN-2001-0542</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-227" comment="File sqlservr.exe version3 less than 428" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL87" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Simple Network Management Protocol (SNMP)</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
			</dates>
			<description>Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via (1) GetRequest, (2) GetNextRequest, and (3) SetRequest messages, as demonstrated by the PROTOS c06-SNMPv1 test suite. NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor. This and other SNMP-related candidates will be updated when more accurate information is available.</description>
			<reference source="CVE">CAN-2002-0013</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-228" comment="the version of snmp.exe is less than 4.0.1381.7134" />
					<criterion test_ref="wrt-263" negate="true" comment="Patch Q314147 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-264" comment="the SNMP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL89" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Multiple UNC Provider (MUP)</product>
			</affected>
			<dates>
				<submitted date="2003-05-13">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request.</description>
			<reference source="CVE">CVE-2002-0151</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-229" comment="File %windir%\system32\drivers\mup.sys version is less than 5.0.2195.5080" />
					<criterion test_ref="wrt-265" negate="true" comment="Patch Q311967 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL90" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-10-20">INTERIM</status_change>
				<modified date="2004-10-20" comment="corrected configuration criterion">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2004-11-03">ACCEPTED</status_change>
			</dates>
			<description>IIS 5.0 allows remote attackers to cause a denial of service via a series of malformed WebDAV requests.</description>
			<reference source="CVE">CVE-2001-0151</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-230" comment="File %windir%\system32\inetsrv\httpext.dll version is less than 0.9.3940.20" />
					<criterion test_ref="wrt-266" negate="true" comment="Patch Q291845 Installed" />
					<criterion test_ref="wrt-249" negate="true" comment="Patch Q293826 Installed" />
					<criterion test_ref="wrt-242" negate="true" comment="Patch Q301625 Installed" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-250" negate="true" comment="Win2K/XP/2003 service pack 2 is installed" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="wrt-541" negate="true" comment="WebDav is disabled(for iis 5.0)" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL92" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
			</dates>
			<description>Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page.</description>
			<reference source="CVE">CVE-2002-0148</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL95" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names.</description>
			<reference source="CVE">CVE-2002-0149</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL96" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if cookies are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-09">INTERIM</status_change>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>The zone determination function in Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to run scripts in the Local Computer zone by embedding the script in a cookie, aka the &quot;Cookie-based Script Execution&quot; vulnerability.</description>
			<reference source="CVE">CVE-2002-0078</reference>
			<status>ACCEPTED</status>
			<version>4</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-18" comment="Internet Explorer 6 is installed" />
					<criterion test_ref="wft-231" comment="the version of mshtml.dll is less than 6.0.2715.400" />
					<criterion test_ref="wrt-203" negate="true" comment="the patch q319282 is installed (Installed Components key)" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-250" comment="cookies are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL98" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">David Proulx</contributor>
				</submitted>
			</dates>
			<description>Buffer overflow in gopher client for Microsoft Internet Explorer 5.1 through 6.0, Proxy Server 2.0, or ISA Server 2000 allows remote attackers to execute arbitrary code via a gopher:// URL that redirects the user to a real or simulated gopher server that sends a long response.</description>
			<reference source="CVE">CAN-2002-0371</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-232" comment="File %windir%\system32\mshtml.dll version is less than 6.0.2719.2200" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration>
					<criterion test_ref="wrt-271" comment="Gopher Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL99" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
				<modified date="2005-03-07" comment="modified wrt-222 - changed pattern match">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-03-09">INTERIM</status_change>
				<status_change date="2005-03-29">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for handling rather than raise an error message, aka the first variant of the &quot;Content Disposition&quot; vulnerability.</description>
			<reference source="CVE">CVE-2002-0193</reference>
			<status>ACCEPTED</status>
			<version>4</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-204" comment="the version of mshtml.dll is less than 6.0.2716.2200" />
					<criterion test_ref="wrt-204" negate="true" comment="the patch q321232 is installed (Installed Components key)" />
					<criterion test_ref="wrt-205" negate="true" comment="the patch q323759 is installed (Installed Components key)" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
					<criterion test_ref="cmp-215" negate="true" comment="Windows 2000 Service Pack 4 (or later) is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL103" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Locator service</product>
			</affected>
			<dates>
				<submitted date="2003-08-27">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.</description>
			<reference source="CVE">CVE-2003-0003</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-233" comment="the version of locator.exe is less than 4.0.1381.7202" />
					<criterion test_ref="wrt-272" negate="true" comment="Patch Q810833 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-273" comment="Locator Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL109" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.</description>
			<reference source="CVE">CAN-2003-0109</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" />
					<criterion test_ref="wft-234" comment="the version of ntdll.dll is less than 5.0.2195.6685" />
					<criterion test_ref="wrt-274" negate="true" comment="the patch q815021 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL117" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>ISA Server 2000</product>
			</affected>
			<dates>
				<submitted date="2003-10-03">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to inject arbitrary web script via a URL containing the script in the domain name portion, which is not properly cleansed in the default error pages (1) 500.htm for &quot;500 Internal Server error&quot; or (2) 404.htm for &quot;404 Not Found.&quot;</description>
			<reference source="CVE">CAN-2003-0526</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-105" comment="ISA Server 2000 is installed" />
					<criterion test_ref="wrt-276" negate="true" comment="ISA2000-KB816456-x86.exe" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL118" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SMB (Server Message Block)</product>
			</affected>
			<dates>
				<submitted date="2003-09-08">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.</description>
			<reference source="CVE">CAN-2003-0345</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" />
					<criterion test_ref="wft-235" comment="File %windir%\system32\Drivers\SRV.SYS is less than 5.0.2195.6699" />
					<criterion test_ref="wrt-277" negate="true" comment="Patch Windows2000-KB817606-x86-ENU.exe Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL121" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>SQL Server 2000</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Yi-Fang Koh</contributor>
				</submitted>
				<modified date="2005-04-08" comment="modified wft-237 - literal string corrected">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-236 - corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-65 - Corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-66 - corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-67 - Corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-68 - Corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<modified date="2005-04-08" comment="modified wft-69 - corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflows in extended stored procedures for Microsoft SQL Server 7.0 and 2000 allow remote attackers to cause a denial of service or execute arbitrary code via a database query with certain long arguments.</description>
			<reference source="CVE">CAN-2002-0154</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-260" comment="SQL Server 2000 is installed" />
					<criterion test_ref="wft-236" comment="the version of sqlservr.exe is less than 2000.80.608.0" />
					<criterion test_ref="wft-237" comment="the version of odsole70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-65" comment="the version of xpqueue.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-66" comment="the version of xprepl.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-67" comment="the version of xplog70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-68" comment="the version of xpweb70.dll is less than 2000.80.606.0" />
					<criterion test_ref="wft-69" comment="the version of xpstar.dll is less than 2000.80.628.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL123" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows 2000</product>
			</affected>
			<dates>
				<submitted date="2003-11-12">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if ActiveX controls are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data binding, which allows remote attackers to execute arbitrary code via an HTML e-mail message or web page.</description>
			<reference source="CVE">CAN-2003-0809</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-256" comment="Internet Explorer 6.0 or IE 6.0 SP1 is installed" />
					<criterion test_ref="wft-238" comment="the version of mshtml.dll is less than 6.0.2800.1264" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
				<configuration operation="AND">
					<criterion test_ref="cmp-75" comment="ActiveX controls are enabled" />
					<criterion test_ref="wrt-280" comment=".hta applications are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL126" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
			</dates>
			<description>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka &quot;Improper Cross Domain Security Validation with dialog box.&quot;</description>
			<reference source="CVE">CVE-2003-1326</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-216" comment="the version of mshtml.dll is less than 6.0.2723.2500" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL127" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Remote Procedure Call (RPC)</product>
			</affected>
			<dates>
				<submitted date="2003-09-15">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed RPC request with a long filename parameter, a different vulnerability than CAN-2003-0352 (Blaster/Nachi) and CAN-2003-0715.</description>
			<reference source="CVE">CAN-2003-0528</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="wft-239" comment="the version of rpcrt4.dll is less than 5.0.2195.6802" />
					<criterion test_ref="wrt-281" negate="true" comment="the patch kb824146 is installed (Hotfix key)" />
				</software>
				<configuration>
					<criterion test_ref="cmp-7" comment="DCOM is enabled on systems with SP3 or later" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL130" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Information Server 5.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the ism.dll ISAPI extension that implements HTR scripting in Internet Information Server (IIS) 4.0 and 5.0 allows attackers to cause a denial of service or execute arbitrary code via HTR requests with long variable names.</description>
			<reference source="CVE">CVE-2002-0071</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-223" comment="IIS major version equals 5" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-205" comment="the version of w3svc.dll is less than 5.0.2195.5269" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
					<criterion test_ref="wrt-224" negate="true" comment="Win2K/XP/2003 service pack 3 (or later) is installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-203" comment="ism.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL132" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names.</description>
			<reference source="CVE">CVE-2002-0149</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL134" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows Script Engine for Jscript</product>
			</affected>
			<dates>
				<submitted date="2004-11-02"/>
				<status_change date="2004-11-03">DRAFT</status_change>
				<status_change date="2004-12-09">INTERIM</status_change>
				<status_change date="2005-01-06">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array index value that enables a heap-based buffer overflow attack.</description>
			<reference source="CVE">CAN-2003-0010</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-1157" comment="jscript.dll version is 5.1, 5.5, or 5.6 " />
					<criterion test_ref="wrt-1" comment="Windows 2000 is installed" />
					<criterion test_ref="cmp-1156" negate="true" comment="The patch js56nen.exe is installed for version 5.1, 5.5, or 5.6" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL136" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 98</windows:platform>
				<windows:platform>Microsoft Windows ME</windows:platform>
				<windows:platform>Microsoft Windows NT</windows:platform>
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<windows:platform>Microsoft Windows XP</windows:platform>
				<windows:platform>Microsoft Windows Server 2003</windows:platform>
				<product>Microsoft Virtual Machine (VM)</product>
			</affected>
			<dates>
				<submitted date="2004-04-30">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-05-25">INTERIM</status_change>
				<status_change date="2004-06-16">ACCEPTED</status_change>
			</dates>
			<description>The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Internet Explorer, allows remote attackers to bypass security checks and execute arbitrary code via a malicious Java applet, aka &quot;Flaw in Microsoft VM Could Enable System Compromise.&quot;</description>
			<reference source="CVE">CAN-2003-0111</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software>
					<criterion test_ref="wft-301" comment="the version of msjava.dll is less than 5.0.3810.0" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL137" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values.</description>
			<reference source="CVE">CVE-2002-0150</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-202" comment="the version of w3svc.dll is less than 4.2.775.1" />
					<criterion test_ref="wrt-217" negate="true" comment="Patch Q319733 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-201" comment="asp.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL139" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Simple Network Management Protocol (SNMP)</product>
			</affected>
			<dates>
				<submitted date="2004-06-08">
					<contributor organization="The MITRE Corporation">Matt Busby</contributor>
				</submitted>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>The default permissions for the SNMP Parameters registry key in Windows NT 4.0 allows remote attackers to read and possibly modify the SNMP community strings to obtain sensitive information or modify network configuration, aka one of the &quot;Registry Permissions&quot; vulnerabilities.</description>
			<reference source="CVE">CAN-2001-0046</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-1011" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition" />
					<criterion test_ref="cmp-1012" comment="For Terminal Server" />
					<criterion test_ref="wrt-454" negate="true" comment="Patch Q265714 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-264" comment="the SNMP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL140" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Microsoft Transaction Server (MTS)</product>
			</affected>
			<dates>
				<submitted date="2004-06-08">
					<contributor organization="The MITRE Corporation">Matt Busby</contributor>
				</submitted>
				<status_change date="2004-06-30">INTERIM</status_change>
				<status_change date="2004-07-12">ACCEPTED</status_change>
			</dates>
			<description>The default permissions for the MTS Package Administration registry key in Windows NT 4.0 allows local users to install or modify arbitrary Microsoft Transaction Server (MTS) packages and gain privileges, aka one of the &quot;Registry Permissions&quot; vulnerabilities.</description>
			<reference source="CVE">CAN-2001-0047</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="cmp-1011" comment="For Windows NT 4.0 Workstation, Server and Enterprise Edition" />
					<criterion test_ref="cmp-1012" comment="For Terminal Server" />
					<criterion test_ref="wrt-454" negate="true" comment="Patch Q265714 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-455" comment="MTS Enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL141" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.01, Internet Explorer 5.01 Service Pack 1</product>
			</affected>
			<dates>
				<submitted date="2003-07-18">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if file downloads are enabled by the current user when local machine settings are not in use.  Changed the status from ACCEPTED to INTERIM">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
			</dates>
			<description>HTML e-mail feature in Internet Explorer 5.5 and earlier allows attackers to execute attachments by setting an unusual MIME type for the attachment, which Internet Explorer does not process correctly.</description>
			<reference source="CVE">CVE-2001-0154</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-264" comment="Internet Explorer 5.01 Installed" />
					<criterion test_ref="wft-240" comment="File %windir%\system32\shdocvw.dll version is less than 5.0.3214.2000" />
					<criterion test_ref="wrt-284" negate="true" comment="the patch q290108 is installed" />
					<criterion test_ref="wrt-285" negate="true" comment="the patch q295106 is installed" />
					<criterion test_ref="wrt-250" negate="true" comment="Win2K/XP/2003 service pack 2 is installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-265" comment="file downloads are enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL142" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows kernel</product>
			</affected>
			<dates>
				<submitted date="2004-11-02">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-11-03">DRAFT</status_change>
				<status_change date="2004-12-09">INTERIM</status_change>
				<status_change date="2005-01-06">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in Windows Kernel allows local users to gain privileges by causing certain error messages to be passed to a debugger.</description>
			<reference source="CVE">CAN-2003-0112</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-536" negate="true" comment="Windows NT Service Pack 6a is installed" />
					<criterion test_ref="wft-436" comment="The version of Ntoskrnl.exe is less than 4.0.1381.7203" />
					<criterion test_ref="wrt-478" negate="true" comment="the patch Q811493 is installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL143" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 6.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
			</dates>
			<description>Internet Explorer 5.01 through 6.0 does not properly perform security checks on certain encoded characters within a URL, which allows a remote attacker to steal potentially sensitive information from a user by redirecting the user to another site that has that information, aka &quot;Encoded Characters Information Disclosure.&quot;</description>
			<reference source="CVE">CVE-2002-1186</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-220" comment="Internet Explorer 6.0 Installed" />
					<criterion test_ref="wft-241" comment="the version of mshtml.dll is less than 6.0.2722.900" />
					<criterion test_ref="wrt-206" negate="true" comment="the patch q328970 is installed (Installed Components key)" />
					<criterion test_ref="wrt-207" negate="true" comment="the patch q324929 is installed (Installed Components key)" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-209" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL144" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Simple Network Management Protocol (SNMP)</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
			</dates>
			<description>Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite. NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor. This and other SNMP-related candidates will be updated when more accurate information is available.</description>
			<reference source="CVE">CAN-2002-0012</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" />
					<criterion test_ref="wft-242" comment="the version of snmp.exe is less than 5.0.2195.4919" />
					<criterion test_ref="wrt-263" negate="true" comment="Patch Q314147 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-264" comment="the SNMP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL145" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Multiple UNC Provider (MUP)</product>
			</affected>
			<dates>
				<submitted date="2003-05-13">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>Buffer overflow in Multiple UNC Provider (MUP) in Microsoft Windows operating systems allows local users to cause a denial of service or possibly gain SYSTEM privileges via a long UNC request.</description>
			<reference source="CVE">CVE-2002-0151</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-243" comment="the version of mup.sys is less than 4.0.1381.7125" />
					<criterion test_ref="wrt-287" negate="true" comment="Patch Q312895 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL146" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>SMB (Server Message Block)</product>
			</affected>
			<dates>
				<submitted date="2004-11-02">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<status_change date="2004-11-03">DRAFT</status_change>
				<status_change date="2004-12-09">INTERIM</status_change>
				<status_change date="2005-01-06">ACCEPTED</status_change>
				<modified date="2005-06-02" comment="Added product">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2005-06-08">INTERIM</status_change>
				<status_change date="2005-06-29">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.</description>
			<reference source="CVE">CAN-2003-0345</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-569" negate="true" comment="Patch Q817606 Installed" />
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wft-566" comment="The version of srv.sys is less than 4.0.1381.7214" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL147" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Windows Shell</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
			</dates>
			<description>Buffer overflow in Windows Shell (used as the Windows Desktop) allows local and possibly remote attackers to execute arbitrary code via a custom URL handler that has not been removed for an application that has been improperly uninstalled.</description>
			<reference source="CVE">CVE-2002-0070</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-65" comment="Windows 2000 (sp3 or earlier) is installed" />
					<criterion test_ref="wft-244" comment="the version of shell32.dll is less than 5.00.3502.4718" />
					<criterion test_ref="wrt-288" negate="true" comment="Patch Q313829 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL158" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows NT 4.0</product>
			</affected>
			<dates>
				<submitted date="2003-04-04">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged process, as demonstrated by DebPloit.</description>
			<reference source="CVE">CVE-2002-0367</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-245" comment="the version of smss.exe is less than 4.0.1381.7152" />
					<criterion test_ref="wrt-262" negate="true" comment="Patch Q320206 Installed" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL159" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Windows NT 4.0</product>
			</affected>
			<dates>
				<submitted date="2003-05-13">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
			</dates>
			<description>In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which could allows remote attackers to gain Domain Administrator privileges on the trusting domain by injecting SIDs from untrusted domains into the authorization data that comes from from the trusted domain.</description>
			<reference source="CVE">CVE-2002-0018</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-246" comment="the version of netlogon.dll is less than 4.0.1381.7092" />
					<criterion test_ref="wrt-243" negate="true" comment="Windows NT 4.0 Security Roll-up Package" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL161" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Simple Network Management Protocol (SNMP)</product>
			</affected>
			<dates>
				<submitted date="2003-10-10">
					<contributor organization="The MITRE Corporation">Harvey Rubinovitz</contributor>
				</submitted>
			</dates>
			<description>Vulnerabilities in a large number of SNMP implementations allow remote attackers to cause a denial of service or gain privileges via SNMPv1 trap handling, as demonstrated by the PROTOS c06-SNMPv1 test suite. NOTE: It is highly likely that this candidate will be SPLIT into multiple candidates, one or more for each vendor. This and other SNMP-related candidates will be updated when more accurate information is available.</description>
			<reference source="CVE">CAN-2002-0012</reference>
			<status>ACCEPTED</status>
			<version>1</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-77" comment="Windows NT 4.0 is installed" />
					<criterion test_ref="wrt-43" negate="true" comment="this is an NT Terminal Server" />
					<criterion test_ref="wft-228" comment="the version of snmp.exe is less than 4.0.1381.7134" />
					<criterion test_ref="wrt-263" negate="true" comment="Patch Q314147 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wrt-264" comment="the SNMP service is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL178" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Internet Explorer 5.5</product>
			</affected>
			<dates>
				<submitted date="2004-01-27">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</submitted>
			</dates>
			<description>Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model to run malicious script or arbitrary programs via dialog boxes, aka &quot;Improper Cross Domain Security Validation with dialog box.&quot;</description>
			<reference source="CVE">CVE-2003-1326</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-271" comment="Internet Explorer 5.5 Installed" />
					<criterion test_ref="wft-247" comment="the version of mshtml.dll is less than 5.50.4923.2500" />
					<criterion test_ref="wrt-208" negate="true" comment="the patch q810847 is installed (Installed Components key)" />
					<criterion test_ref="wrt-252" negate="true" comment="the patch q813489 is installed (Installed Components key)" />
					<criterion test_ref="wrt-210" negate="true" comment="the patch q818529 is installed (Installed Components key)" />
					<criterion test_ref="wrt-211" negate="true" comment="the patch q822925 is installed (Installed Components key)" />
					<criterion test_ref="wrt-212" negate="true" comment="the patch q828750 is installed (Installed Components key)" />
					<criterion test_ref="wrt-19" negate="true" comment="the patch q824145 is installed (Installed Components key)" />
				</software>
			</criteria>
		</definition>
		<definition id="OVAL182" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows NT</windows:platform>
				<product>Internet Information Server 4.0</product>
			</affected>
			<dates>
				<submitted date="2004-01-14">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<status_change date="2004-03-09">ACCEPTED</status_change>
			</dates>
			<description>Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka &quot;Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise.&quot;</description>
			<reference source="CVE">CVE-2002-0364</reference>
			<status>ACCEPTED</status>
			<version>3</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-214" comment="IIS 4.0 Major Version" />
					<criterion test_ref="wrt-215" comment="IIS minor version equals 0" />
					<criterion test_ref="wft-248" comment="File %windir%\system32\inetsrv\ism.dll version is less than 4.2.776.1" />
					<criterion test_ref="wrt-289" negate="true" comment="Patch Q321599 Installed" />
					<criterion test_ref="wrt-218" negate="true" comment="Patch Q327696 Installed" />
					<criterion test_ref="wrt-219" negate="true" comment="Patch Q811114 Installed" />
				</software>
				<configuration>
					<criterion test_ref="wmt-203" comment="ism.dll mapping exists" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL185" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows XP</windows:platform>
				<product>Authenticode</product>
			</affected>
			<dates>
				<submitted date="2003-10-29">
					<contributor organization="The MITRE Corporation">Tiffany Bergeron</contributor>
				</submitted>
				<modified date="2004-03-04" comment="Added the configuration check to see if downloading of signed ActiveX controls are enabled by the current user when local machine settings are not in use.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<modified date="2004-03-05" comment="Fixed the logic that checks for one version of the file if no sp is installed and a different version if sp1 is installed.">
					<contributor organization="The MITRE Corporation">Andrew Buttner</contributor>
				</modified>
				<status_change date="2004-03-25">ACCEPTED</status_change>
				<modified date="2004-09-13" comment="The compound test that includes SP1 or earlier has been added">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2004-09-13" comment="">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-09-15">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
			</dates>
			<description>The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers execute arbitrary code without user approval.</description>
			<reference source="CVE">CAN-2003-0660</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="cmp-273" comment="a vulnerable version of cryptui.dll exists" />
					<criterion test_ref="wrt-293" negate="true" comment="Patch WindowsXP-KB823182-x86-ENU Installed" />
					<criterion test_ref="cmp-66" comment="Windows XP (sp1 or earlier) is installed" />
				</software>
				<configuration>
					<criterion test_ref="cmp-275" comment="downloading of signed ActiveX controls is enabled" />
				</configuration>
			</criteria>
		</definition>
		<definition id="OVAL188" class="vulnerability">
			<affected family="windows">
				<windows:platform>Microsoft Windows 2000</windows:platform>
				<product>Microsoft Word 2000</product>
			</affected>
			<dates>
				<submitted date="2004-08-25">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</submitted>
				<modified date="2004-08-25" comment="Added word 2000 and winword.exe information">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<modified date="2004-08-25" comment="changed to word 2000">
					<contributor organization="The MITRE Corporation">Christine Walzer</contributor>
				</modified>
				<status_change date="2004-08-25">DRAFT</status_change>
				<status_change date="2004-09-09">INTERIM</status_change>
				<status_change date="2004-09-29">ACCEPTED</status_change>
				<modified date="2005-04-11" comment="modified wft-470 - wft-470 corrected literal string">
					<contributor organization="The MITRE Corporation">Ingrid Skoog</contributor>
				</modified>
				<status_change date="2005-04-11">INTERIM</status_change>
				<status_change date="2005-04-27">ACCEPTED</status_change>
			</dates>
			<description>Microsoft Word 2002, 2000, 97, and 98(J) does not properly check certain properties of a document, which allows attackers to bypass the macro security model and automatically execute arbitrary macros via a malicious document.</description>
			<reference source="CVE">CAN-2003-0664</reference>
			<status>ACCEPTED</status>
			<version>2</version>
			<criteria>
				<software operation="AND">
					<criterion test_ref="wrt-132" comment="Word 2000 is installed" />
					<criterion test_ref="wft-470" comment="the version of winword.exe is less than 9.0.0.7924"