Microsoft Windows Remote Desktop Protocol Server Private Key Disclosure Vulnerability
BID:13818
Info
Microsoft Windows Remote Desktop Protocol Server Private Key Disclosure Vulnerability
| Bugtraq ID: | 13818 |
| Class: | Design Error |
| CVE: |
CVE-2005-1794 |
| Remote: | Yes |
| Local: | No |
| Published: | May 30 2005 12:00AM |
| Updated: | Jul 12 2009 02:56PM |
| Credit: | Discovery is credited to Massimiliano Montoro <[email protected]>. |
| Vulnerable: |
Microsoft RDP 5.2 Microsoft RDP 5.1 Microsoft RDP 5.0 Microsoft RDP 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows Remote Desktop Protocol Server Private Key Disclosure Vulnerability
The vulnerability presents itself because a private key that is used to sign the Terminal Server public key is hardcoded in a DLL.
This can allow the attacker to disclose the key and calculate a valid signature to carry out man in the middle attacks.
An attacker could therefore cause the client to connect to a server under their control and send the client a public key to which they possess the private key.
The vulnerability presents itself because a private key that is used to sign the Terminal Server public key is hardcoded in a DLL.
This can allow the attacker to disclose the key and calculate a valid signature to carry out man in the middle attacks.
An attacker could therefore cause the client to connect to a server under their control and send the client a public key to which they possess the private key.
Exploit / POC
Microsoft Windows Remote Desktop Protocol Server Private Key Disclosure Vulnerability
An exploit to leverage this issue is available as a part of Cain & Abel version 2.7.
An exploit to leverage this issue is available as a part of Cain & Abel version 2.7.
Solution / Fix
Microsoft Windows Remote Desktop Protocol Server Private Key Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Windows Remote Desktop Protocol Server Private Key Disclosure Vulnerability
References:
References:
- Remote Desktop Protocol, the Good the Bad and the Ugly (Massimiliano Montoro
)