Vulnerability Description
Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Remote Desktop Connection | 5.1.2600.2180 |
| Microsoft | Windows Terminal Services Using Rdp | 5.2 |
References
- http://secunia.com/advisories/15605/
- http://www.oxid.it/downloads/rdp-gbu.pdfVendor Advisory
- http://www.securityfocus.com/bid/13818
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
- http://secunia.com/advisories/15605/
- http://www.oxid.it/downloads/rdp-gbu.pdfVendor Advisory
- http://www.securityfocus.com/bid/13818
- https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3
FAQ
What is CVE-2005-1794?
CVE-2005-1794 is a vulnerability with a CVSS score of 6.4 (MEDIUM). Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of leg...
How severe is CVE-2005-1794?
CVE-2005-1794 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-1794?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Remote Desktop Connection, Microsoft Windows Terminal Services Using Rdp.