Vulnerability Name: | CVE-2006-2380 (CCN-26836) | ||||||||
Assigned: | 2006-06-13 | ||||||||
Published: | 2006-06-13 | ||||||||
Updated: | 2019-04-30 | ||||||||
Summary: | Microsoft Windows 2000 SP4 does not properly validate an RPC server during mutual authentication over SSL, which allows remote attackers to spoof an RPC server, aka the "RPC Mutual Authentication Vulnerability." | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-287 | ||||||||
Vulnerability Consequences: | Other | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-2380 Source: CCN Type: SA20637 Microsoft Windows RPC Mutual Authentication Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory 20637 Source: CCN Type: SECTRACK ID: 1016289 Microsoft RPC Mutual Authentication Bug Lets Remote Users Spoof Other Systems Source: SECTRACK Type: Patch 1016289 Source: CCN Type: ASA-2006-126 Windows Security Updates for June 2006 - (MS06-021 - MS06-032) Source: CCN Type: Microsoft Security Bulletin MS13-062 Vulnerability in Remote Procedure Call Could Allow Elevation of Privilege (2849470) Source: CCN Type: Microsoft Security Bulletin MS14-047 Vulnerability in LRPC Could Allow Security Feature Bypass (2978668) Source: CCN Type: Microsoft Security Bulletin MS16-007 Security Update for Microsoft Windows to Address Remote Code Execution (3124901) Source: CCN Type: Microsoft Security Bulletin MS16-014 Security update for Microsoft Windows to Address Remote Code Execution (3134228) Source: CCN Type: Microsoft Security Bulletin MS16-047 Security Update for SAM and LSAD Remote Protocols (3148527) Source: CCN Type: Microsoft Security Bulletin MS16-061 Security Update for Microsoft RPC (3155520) Source: CCN Type: Microsoft Security Bulletin MS16-075 Security Update for Windows SMB Server (3164038) Source: CCN Type: Microsoft Security Bulletin MS16-076 Security Update for Netlogon (3167691) Source: CCN Type: Microsoft Security Bulletin MS16-101 Security Update for Windows Authentication Methods (3178465) Source: CCN Type: Microsoft Security Bulletin MS16-110 Security Update for Windows (3178467) Source: CCN Type: Microsoft Security Bulletin MS16-111 Security Update for Windows Kernel (3186973) Source: CCN Type: Microsoft Security Bulletin MS16-120 Security Update for Microsoft Graphics Component (3192884) Source: CCN Type: Microsoft Security Bulletin MS16-122 Security Update for Microsoft Video Control (3195360) Source: CCN Type: Microsoft Security Bulletin MS16-123 Security Update for Kernel-Mode Drivers (3192892) Source: CCN Type: Microsoft Security Bulletin MS16-124 Security Update for Windows Registry (3193227) Source: CCN Type: Microsoft Security Bulletin MS16-126 Security Update for Microsoft Internet Messaging API (3196067) Source: CCN Type: Microsoft Security Bulletin MS16-131 Security Update for Microsoft Video Control (3199151) Source: CCN Type: Microsoft Security Bulletin MS16-139 Security Update for Windows Kernel (3199720) Source: CCN Type: Microsoft Security Bulletin MS16-155 Security Update for .NET Framework (3205640) Source: CCN Type: Microsoft Security Bulletin MS17-006 Cumulative Security Update for Internet Explorer (4013073) Source: CCN Type: Microsoft Security Bulletin MS17-013 Security Update for Microsoft Graphics Component (4013075) Source: CCN Type: Microsoft Security Bulletin MS06-031 Vulnerability in RPC Mutual Authentication Could Allow Spoofing (917736) Source: CCN Type: Microsoft Security Bulletin MS07-058 Vulnerability in RPC Could Allow Denial of Service (933729) Source: CCN Type: Microsoft Security Bulletin MS09-026 Vulnerability in RPC Could Allow Elevation of Privilege (970238) Source: CCN Type: Microsoft Security Bulletin MS10-066 Vulnerability in Remote Procedure Call Could Allow Remote Code Execution (982802) Source: CCN Type: Microsoft Security Bulletin MS10-084 Vulnerability in Windows Local Procedure Call Could Cause Elevation of Privilege (2360937) Source: OSVDB Type: UNKNOWN 26438 Source: CCN Type: OSVDB ID: 26438 Microsoft Windows RPC Mutual Authentication Server Spoofing Source: BID Type: Patch 18389 Source: CCN Type: BID-18389 Microsoft Windows RPC Mutual Authentication Service Spoofing Vulnerability Source: VUPEN Type: Vendor Advisory ADV-2006-2328 Source: MS Type: UNKNOWN MS06-031 Source: XF Type: UNKNOWN win-rpc-mutual-authentication-spoofing(26836) Source: XF Type: UNKNOWN win-rpc-mutual-authentication-spoofing(26836) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:1763 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |