Microsoft Windows 2000/NT Terminal Server Service RDP DoS Vulnerability
BID:3445
Info
Microsoft Windows 2000/NT Terminal Server Service RDP DoS Vulnerability
| Bugtraq ID: | 3445 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2001 12:00AM |
| Updated: | Oct 18 2001 12:00AM |
| Credit: | Discovered by Luciano Martins and published in a Microsoft Security Bulletin MS01-052 on October 18, 2001. |
| Vulnerable: |
Microsoft RDP 5.0 Microsoft RDP 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows 2000/NT Terminal Server Service RDP DoS Vulnerability
Due to a flaw in the implementation of RDP in Windows 2000/NT Terminal Server, it is possible for a remote user to cause a host to stop responding.
Sending malformed RDP packets to a host could cause a denial of services, potentially impacting the Terminal service and other applications running on the affected host.
Due to a flaw in the implementation of RDP in Windows 2000/NT Terminal Server, it is possible for a remote user to cause a host to stop responding.
Sending malformed RDP packets to a host could cause a denial of services, potentially impacting the Terminal service and other applications running on the affected host.
Solution / Fix
Microsoft Windows 2000/NT Terminal Server Service RDP DoS Vulnerability
Solution:
Users of Windows 2000 Datacenter Server should contact their equipment manufacturer for details on obtaining patches.
Users that installed the original patches may have experienced Terminal Service functionality issues. Microsoft has re-released the following patches which rectify this issue. These patches were re-released on October 22nd, 2001.
Microsoft found that the patch released on October 22nd, 2001 was affected by a denial of service vulnerability. Microsoft has updated the patch.
Microsoft RDP 4.0
Microsoft RDP 5.0
Solution:
Users of Windows 2000 Datacenter Server should contact their equipment manufacturer for details on obtaining patches.
Users that installed the original patches may have experienced Terminal Service functionality issues. Microsoft has re-released the following patches which rectify this issue. These patches were re-released on October 22nd, 2001.
Microsoft found that the patch released on October 22nd, 2001 was affected by a denial of service vulnerability. Microsoft has updated the patch.
Microsoft RDP 4.0
-
Microsoft Q307454
This patch addresses RDP 4.0 included with Windows NT 4.0 Terminal Server.
http://download.microsoft.com/download/winntsp/Patch/q307454/NT4/EN-US /Q307454i.exe
Microsoft RDP 5.0
-
Microsoft Q307454
This patch addresses RDP 5.0 included with Windows 2000.
http://download.microsoft.com/download/win2000platform/Patch/q307454/N T5/EN-US/Q307454_W2K_SP3_x86_en.exe