IP Address Spoofing Vulnerability in Microsoft Windows Terminal Services
A vulnerability exists in Microsoft Windows Terminal Services that might let a hacker cause both the Terminal Services Manager and the Windows Event Log to record a spoofed IP address for Terminal Services connections.
November 19, 2001
Reported November 19, 2001, byXato Network Security.
VERSIONS AFFECTED
Microsoft Windows XP
Microsoft Windows 2000
DESCRIPTION
Avulnerability exists in Microsoft Windows Terminal Services that might let ahacker cause both the Terminal Services Manager and the Windows Event Log torecord a spoofed IP address for Terminal Services connections. Thisvulnerability stems from Windows Terminal Services use of the connectingclient’s internal IP address. By using Network Address Translation (NAT), anattacker can fool Windows Terminal Services into thinking that the client isconnecting from a different IP address.
VENDOR RESPONSE
Thevendor, Microsoft, has acknowledged thisvulnerability and will issue a fix as part of Windows 2000 Service Pack 3.
CREDIT
Discovered by Sozniof Xato Network Security.
Read more about:
MicrosoftAbout the Author
You May Also Like