CVE-2002-0863
Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 22.0%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol."
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 21.98% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/.net windows server · microsoft/windows 2000 · microsoft/windows 2000 terminal services · microsoft/windows nt · microsoft/windows xp
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=103235960119404&w=2
- http://marc.info/?l=bugtraq&m=103236181522253&w=2
- http://www.iss.net/security_center/static/10121.phpVendor Advisory
- http://www.iss.net/security_center/static/10122.php
- http://www.kb.cert.org/vuls/id/865833US Government Resource
- http://www.securityfocus.com/bid/5711
- http://www.securityfocus.com/bid/5712
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-051
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A199
- http://marc.info/?l=bugtraq&m=103235960119404&w=2
- http://marc.info/?l=bugtraq&m=103236181522253&w=2
- http://www.iss.net/security_center/static/10121.phpVendor Advisory
- http://www.iss.net/security_center/static/10122.php
- http://www.kb.cert.org/vuls/id/865833US Government Resource
- http://www.securityfocus.com/bid/5711
- http://www.securityfocus.com/bid/5712
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-051
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A199
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.