openVAS - Microsoft RDP Server Private Key Information Disclosure Vulnerability - false Alarm?
Posted
by
huebkov
on Server Fault
See other posts from Server Fault
or by huebkov
Published on 2012-09-06T21:01:56Z
Indexed on
2012/09/06
21:41 UTC
Read the original article
Hit count: 175
I performed a openVAS scan on a Windows Server 2008 R2
and got a report for a high threat level vulnerability called Microsoft RDP Server Private Key Information Disclosure Vulnerability
. An remote attacker could perform a man-in-the-middle
attack to gain access to a RDP session.
Affected Software is Microsoft RDP 5.2 and below.
My server uses RDP 7.1, is this alarm a false alarm?
Security Advisor Pages say: Solution Status Unpatched, No remedy...
References
http://secunia.com/advisories/15605/
http://xforce.iss.net/xforce/xfdb/21954/
http://www.oxid.it/downloads/rdp-gbu.pdf
CVE: CVE-2005-1794
BID:13818
© Server Fault or respective owner