CVE-2002-0863: Weak Encryption
Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0863?
CVE-2002-0863 is considered a high-severity vulnerability due to the risk of remote attackers gaining unauthorized access to session data.
How do I fix CVE-2002-0863?
To mitigate CVE-2002-0863, apply the latest service packs and updates for Windows 2000 and Windows XP that address the weak encryption issue.
What systems are affected by CVE-2002-0863?
CVE-2002-0863 impacts Microsoft Windows 2000, Windows XP, and specific versions of Windows NT using RDP.
What type of attack is possible due to CVE-2002-0863?
CVE-2002-0863 allows attackers to sniff unencrypted session data, potentially exposing sensitive information.
Is CVE-2002-0863 still a concern in modern systems?
Although CVE-2002-0863 primarily affects older systems, any legacy systems still in use could be vulnerable to exploitation.