openVAS - Microsoft RDP Server Private Key Information Disclosure Vulnerability - false Alarm?

Posted by huebkov on Server Fault See other posts from Server Fault or by huebkov
Published on 2012-09-06T21:01:56Z Indexed on 2012/09/06 21:41 UTC
Read the original article Hit count: 175

I performed a openVAS scan on a Windows Server 2008 R2 and got a report for a high threat level vulnerability called Microsoft RDP Server Private Key Information Disclosure Vulnerability. An remote attacker could perform a man-in-the-middle attack to gain access to a RDP session.

Affected Software is Microsoft RDP 5.2 and below.
My server uses RDP 7.1, is this alarm a false alarm?

Security Advisor Pages say: Solution Status Unpatched, No remedy...

References
http://secunia.com/advisories/15605/
http://xforce.iss.net/xforce/xfdb/21954/
http://www.oxid.it/downloads/rdp-gbu.pdf
CVE: CVE-2005-1794
BID:13818

© Server Fault or respective owner

Related posts about security

Related posts about windows-server-2008-r2