First published: Wed Jun 01 2005(Updated: )
Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Terminal Services using RDP | =5.2 | |
Microsoft Remote Desktop | =5.1.2600.2180 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1794 is considered a critical vulnerability due to its potential for enabling man-in-the-middle attacks.
To fix CVE-2005-1794, it is recommended to upgrade to a patched version of Windows or apply relevant security updates provided by Microsoft.
CVE-2005-1794 affects Microsoft Windows Terminal Services using RDP 5.2 and Microsoft Remote Desktop Connection version 5.1.2600.2180.
CVE-2005-1794 can facilitate man-in-the-middle attacks, allowing attackers to spoof public keys of legitimate servers.
While CVE-2005-1794 primarily affects older systems, any outdated software using RDP may still be susceptible to similar vulnerabilities.