Microsoft Windows Remote Desktop Protocol Server Key Verification Vulnerability
BID:7258
Info
Microsoft Windows Remote Desktop Protocol Server Key Verification Vulnerability
| Bugtraq ID: | 7258 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 02 2003 12:00AM |
| Updated: | Apr 02 2003 12:00AM |
| Credit: | Discovery is credited to Erik Forsberg <[email protected]>. |
| Vulnerable: |
Microsoft RDP 5.2 Microsoft RDP 5.1 Microsoft RDP 5.0 Microsoft RDP 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows Remote Desktop Protocol Server Key Verification Vulnerability
The Windows Remote Desktop Protocol (RDP) clients do not attempt to validate the public key of the server to which they are connecting. This makes a man in the middle attack possible.
The Windows Remote Desktop Protocol (RDP) clients do not attempt to validate the public key of the server to which they are connecting. This makes a man in the middle attack possible.
Exploit / POC
Microsoft Windows Remote Desktop Protocol Server Key Verification Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Windows Remote Desktop Protocol Server Key Verification Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Windows Remote Desktop Protocol Server Key Verification Vulnerability
References:
References:
- Technet Security (Microsoft)
- Microsoft Terminal Services vulnerable to MITM-attacks. (Erik Forsberg
) - Re: Microsoft Terminal Services vulnerable to MITM-attacks. (Carlos Branco
)