Microsoft Windows Insecure Random Number Generator Information Disclosure Weakness
BID:26495
Info
Microsoft Windows Insecure Random Number Generator Information Disclosure Weakness
| Bugtraq ID: | 26495 |
| Class: | Design Error |
| CVE: |
CVE-2007-6043 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 19 2007 12:00AM |
| Updated: | Dec 18 2007 08:05PM |
| Credit: | Zvi Gutterman and Benny Pinkas are credited with the discovery of this vulnerability. |
| Vulnerable: |
Microsoft Windows XP Tablet PC Edition SP2 Microsoft Windows XP Tablet PC Edition SP1 Microsoft Windows XP Tablet PC Edition Microsoft Windows XP Professional x64 Edition SP2 Microsoft Windows XP Professional x64 Edition Microsoft Windows XP Professional SP2 Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Media Center Edition SP2 Microsoft Windows XP Media Center Edition SP1 Microsoft Windows XP Media Center Edition Microsoft Windows XP Home SP2 Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows XP 64-bit Edition Version 2003 SP1 Microsoft Windows XP 64-bit Edition Version 2003 Microsoft Windows XP 64-bit Edition SP1 Microsoft Windows XP 64-bit Edition Microsoft Windows XP 0 Microsoft Windows Workflow Foundation 3.0.4203 .2 Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows Insecure Random Number Generator Information Disclosure Weakness
Microsoft Windows is prone to an information-disclosure weakness.
An attacker can exploit this issue to weaken encryption and other security-related algorithms, which may aid in further attacks.
This issue affects Microsoft Windows 2000 and Microsoft Windows XP.
Microsoft Windows is prone to an information-disclosure weakness.
An attacker can exploit this issue to weaken encryption and other security-related algorithms, which may aid in further attacks.
This issue affects Microsoft Windows 2000 and Microsoft Windows XP.
Exploit / POC
Solution / Fix
Microsoft Windows Insecure Random Number Generator Information Disclosure Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Microsoft Windows Insecure Random Number Generator Information Disclosure Weakness
References:
References:
- Cryptanalysis of the Random Number Generator of the Windows Operating System (Zvi Gutterman and Benny Pinkas)
- Microsoft confirms that XP contains random number generator bug (Computerworld)
- Microsoft Windows Homepage (Microsoft )
- Security loophole in Windows 2000 exposes users' private info (Howard Dahdah )