CVE-2005-1205: Medium severity Microsoft Windows 2003 Server vulnerability
Published Jun 14, 2005
·Updated
The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENVUSERVAR command.
Affected Software
4 affected components
Microsoft Windows 2003 Server=web
Microsoft Windows 2003 Server=enterprise
Microsoft Windows 2003 Server=standard
Microsoft Windows 2003 Server=r2
Remediation
Patch Available
Patch Available
Event History
Jun 14, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1205?
CVE-2005-1205 has a moderate severity level due to its potential to expose sensitive environment variables.
2
How do I fix CVE-2005-1205?
To fix CVE-2005-1205, disable the Telnet client or apply relevant patches and updates provided by Microsoft.
3
What systems are affected by CVE-2005-1205?
CVE-2005-1205 affects the Telnet client on Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX.
4
Can CVE-2005-1205 be exploited remotely?
Yes, CVE-2005-1205 can be exploited remotely by attackers sending SEND ENV_USERVAR commands.
5
What vulnerabilities does CVE-2005-1205 introduce?
CVE-2005-1205 introduces risks related to unauthorized access to sensitive environment variables.