IP Address Spoofing Vulnerability in Microsoft Windows Terminal Services

A vulnerability exists in Microsoft Windows Terminal Services that might let a hacker cause both the Terminal Services Manager and the Windows Event Log to record a spoofed IP address for Terminal Services connections.

Ken Pfeil

November 19, 2001

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported November 19, 2001, byXato Network Security.

VERSIONS AFFECTED

 

  • Microsoft Windows XP

  • Microsoft Windows 2000

 

DESCRIPTION
Avulnerability exists in Microsoft Windows Terminal Services that might let ahacker cause both the Terminal Services Manager and the Windows Event Log torecord a spoofed IP address for Terminal Services connections. Thisvulnerability stems from Windows Terminal Services use of the connectingclient’s internal IP address. By using Network Address Translation (NAT), anattacker can fool Windows Terminal Services into thinking that the client isconnecting from a different IP address.

 

VENDOR RESPONSE

Thevendor, Microsoft, has acknowledged thisvulnerability and will issue a fix as part of Windows 2000 Service Pack 3.

 

CREDIT
Discovered by Sozniof Xato Network Security.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like