Vulnerability record · CVE-2002-1214 · published 28 October 2002
CVE-2002-1214: Microsoft PPTP Service buffer overflow on Windows XP and 2000
Microsoft · Windows 2000
The Microsoft PPTP Service on Windows XP and Windows 2000 contains a buffer overflow triggered by a PPTP packet with malformed control data. A remote, unauthenticated attacker can hang the service and possibly execute arbitrary code. The record is old and thin on technical detail, but the flaw is network-reachable and pre-authentication.
Description
Buffer overflow in Microsoft PPTP Service on Windows XP and Windows 2000 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a certain PPTP packet with malformed control data.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe flaw is remotely reachable without authentication and can lead to code execution, and EPSS is high, though the affected platforms are legacy and no KEV listing or known exploit is recorded.
What it is
The Microsoft PPTP Service on Windows XP and Windows 2000 contains a buffer overflow triggered by a PPTP packet with malformed control data. A remote, unauthenticated attacker can hang the service and possibly execute arbitrary code. The record is old and thin on technical detail, but the flaw is network-reachable and pre-authentication.
Impact
An attacker can cause a denial of service by hanging the PPTP service and may be able to execute arbitrary code in the service context. Successful code execution would give the attacker a foothold on the affected host.
Attack surface
Reachable over the network via PPTP traffic to the affected service, as reflected in the AV:N/AC:L/Au:N vector. No authentication or user interaction is required.
Exploitation
CVE-2002-1214 is not listed in CISA KEV and no ransomware use is documented, but EPSS is high at roughly 0.51 (98.9th percentile), indicating elevated predicted exploitation activity. Reference tags include only a Vendor Advisory, with no public exploit tag supplied.
What to do
- Apply the Microsoft security bulletin MS02-063 update for Windows XP and Windows 2000.
- Disable or block PPTP (TCP 1723 and GRE) where it is not required.
- Restrict PPTP access to trusted networks and hosts using firewall rules.
- Upgrade or migrate off Windows 2000 and Windows XP, which are long past end of support.
Detection
- Monitor for PPTP service crashes, hangs or unexpected restarts on Windows 2000 and XP hosts.
- Inspect network traffic for malformed PPTP control packets targeting TCP 1723 or GRE.
- Review host logs for unusual process activity or code execution originating from the PPTP service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2002-1214 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2002-1214), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.