Microsoft Windows 2000 Server Terminal Services Failure To Lock Terminal Vulnerability
BID:4095
Info
Microsoft Windows 2000 Server Terminal Services Failure To Lock Terminal Vulnerability
| Bugtraq ID: | 4095 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 11 2002 12:00AM |
| Updated: | Feb 11 2002 12:00AM |
| Credit: | Steve Shockley <[email protected]> is credited with discovering this issue. |
| Vulnerable: |
Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows 2000 Server Terminal Services Failure To Lock Terminal Vulnerability
It is possible for an administrator to log in to a Microsoft Windows 2000 Server using the Terminal Services client. This may be performed from a desktop that is not logged in as an administrative user.
Under some circumstances, a situation arises when the terminal will not be locked after a disconnect via the Terminal Services client. This occurs when a session is left idle until the screensaver is activated, and then the user disconnects using the Terminal Services client. Upon reconnection, the terminal will fail to lock itself when left idle for any amount of time.
This may create a false sense of security, as the user expects that the terminal will lock itself if left idle. An attacker with physical access to the desktop may capitalize upon this issue.
While this issue has been reported for Microsoft Windows 2000 Server specifically, there may be a possibility that other versions are affected by this vulnerability.
It is possible for an administrator to log in to a Microsoft Windows 2000 Server using the Terminal Services client. This may be performed from a desktop that is not logged in as an administrative user.
Under some circumstances, a situation arises when the terminal will not be locked after a disconnect via the Terminal Services client. This occurs when a session is left idle until the screensaver is activated, and then the user disconnects using the Terminal Services client. Upon reconnection, the terminal will fail to lock itself when left idle for any amount of time.
This may create a false sense of security, as the user expects that the terminal will lock itself if left idle. An attacker with physical access to the desktop may capitalize upon this issue.
While this issue has been reported for Microsoft Windows 2000 Server specifically, there may be a possibility that other versions are affected by this vulnerability.
Exploit / POC
Microsoft Windows 2000 Server Terminal Services Failure To Lock Terminal Vulnerability
There is no exploit required.
There is no exploit required.
References
Microsoft Windows 2000 Server Terminal Services Failure To Lock Terminal Vulnerability
References:
References:
- Terminal doesn't lock after disconnect in Terminal Services (Steve Shockley
)