Multiple Vulnerabilities in Microsoft RDP
Two vulnerabilities exist in Microsoft RDP. The first vulnerability is an information disclosure vulnerability that forwards unencrypted checksums of plain-text data under XP and Win2K.
September 19, 2002
Reported September 18, 2002, byMicrosoft.
VERSIONS AFFECTED
· Windows XP with Remote Desktop enabled
· Windows 2000 Server Terminal Services
DESCRIPTION
Two vulnerabilities exist inMicrosoft RDP. The first vulnerability is an information-disclosurevulnerability that forwards unencrypted checksums of plaintext data under XPand Win2K. An attacker can use these checksums to conduct a cryptanalytic attackto recover session traffic. The second vulnerability is a Denial of Service(DoS) condition in XP’s Remote Desktop service when this service uses RDP. By sending speciallymalformed packets to the service (which by default runs on TCP port 3389), anattacker can crash the vulnerable system.
VENDOR RESPONSE
Thevendor, Microsoft, has released SecurityBulletin MS02-051(Cryptographic Flaw inRDP Protocol can Lead to Information Disclosure)to address these vulnerabilities, and recommends that affected users apply theappropriate patch mentioned in the bulletin.
CREDIT
Discoveredby Microsoft.
Read more about:
MicrosoftAbout the Author
You May Also Like