CVE-2005-1794
Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 16.3%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.
- CVSS 3.1
- 7.4 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 16.32% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/remote desktop connection · microsoft/windows terminal services using rdp
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/15605/
- http://www.oxid.it/downloads/rdp-gbu.pdfVendor Advisory
- http://www.securityfocus.com/bid/13818
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12441
- http://secunia.com/advisories/15605/
- http://www.oxid.it/downloads/rdp-gbu.pdfVendor Advisory
- http://www.securityfocus.com/bid/13818
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12441
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.