SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2002-0863

Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka…

MEDIUM 5.0EPSS 22.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 22.0%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol."

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
21.98% probability · 98th percentile
CISA KEV
Not listed
Affected
microsoft/.net windows server · microsoft/windows 2000 · microsoft/windows 2000 terminal services · microsoft/windows nt · microsoft/windows xp
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.