First published: Wed Aug 10 2005(Updated: )
Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2003 Server | =web | |
Microsoft Windows 2003 Server | =enterprise | |
Microsoft Windows XP | =gold | |
Microsoft Windows 2000 | ||
Microsoft Windows 2003 Server | =standard | |
Microsoft Windows 2003 Server | =r2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1982 is classified as a high-severity vulnerability due to the potential for man-in-the-middle attacks.
Mitigation of CVE-2005-1982 can be achieved by applying relevant patches and avoiding the use of PKINIT with vulnerable systems.
CVE-2005-1982 affects Microsoft Windows 2000, Windows XP, and Windows Server 2003.
CVE-2005-1982 can allow a local user to spoof a server, compromising the integrity of PKINIT smart card authentication.
Disabling PKINIT or implementing additional authentication measures may serve as a temporary workaround for CVE-2005-1982.