SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2001-1571

The Remote Desktop client in Windows XP sends the most recent user account name in cleartext, which could allow remote attackers to obtain terminal server user account names via sniffing.

MEDIUM 5.0EPSS 13.1%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 13.1%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

The Remote Desktop client in Windows XP sends the most recent user account name in cleartext, which could allow remote attackers to obtain terminal server user account names via sniffing.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
13.09% probability · 96th percentile
CISA KEV
Not listed
Affected
microsoft/windows xp
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.