Vulnerability Name:

CCN-11696

Published:2003-04-01
Updated:2003-04-01
Summary:Multiple Microsoft Windows products could allow a remote attacker to spoof a server's public key and perform a man-in-the-middle attack. This vulnerability is caused by improper verification of a server's public key when a Remote Data Protocol (RDP) connection is established. An attacker could use this vulnerability to develop session keys and obtain sensitive information in plain text.

Note: Citrix ICA Client and Cain & Abel are also vulnerable.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Consequences:Bypass Security
References:Source: CCN
Type: BugTraq Mailing List, Tue Apr 01 2003 - 16:05:44 CST
Microsoft Terminal Services vulnerable to MITM-attacks.

Source: CCN
Type: BugTraq Mailing List, Thu Apr 03 2003 - 23:32:39 CST
Re: Microsoft Terminal Services vulnerable to MITM-attacks.

Source: CCN
Type: BugTraq Mailing List, Thu Apr 10 2003 - 09:18:37 CDT
Re: Microsoft Terminal Services vulnerable to MITM-attacks.

Source: CCN
Type: BID-7258
Microsoft Windows Remote Desktop Protocol Server Key Verification Vulnerability

Source: CCN
Type: BID-7276
Citrix ICA Client Server Key Verification Vulnerability

Source: XF
Type: UNKNOWN
win2k-terminal-mitm(11696)

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/o:microsoft:windows_2000:*:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_2000_advanced_server:*:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_2000:::datacenter_server:*:*:*:*:*
  • OR cpe:/a:citrix:ica_client:-:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_xp:::home:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_xp:::professional:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_2003_server:-::~~datacenter~~~:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_2003_server:-::~~enterprise~~~:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_2003_server:-::~~standard~~~:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_2003_server:web:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_2003_server:*:*:*:*:*:*:*:*
  • OR cpe:/o:microsoft:windows_2000:::server:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    microsoft windows 2000 *
    microsoft windows 2000 advanced server *
    microsoft windows 2000
    citrix ica client -
    microsoft windows xp
    microsoft windows xp
    microsoft windows 2003 server -
    microsoft windows 2003 server -
    microsoft windows 2003 server -
    microsoft windows 2003 server web
    microsoft windows 2003 server *
    microsoft windows 2000