CVE-2005-3170: Medium severity microsoft windows 2000 vulnerability
Published Oct 6, 2005
·Updated
The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which could allow attackers to trick users into believing that they are accessing a trusted site.
Affected Software
1 affected component
Microsoft Windows 2000=sp4
Remediation
Patch Available
Patch Available
Event History
Oct 6, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3170?
CVE-2005-3170 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2005-3170?
To mitigate CVE-2005-3170, it is recommended to apply Update Rollup 1 for Service Pack 4 on Microsoft Windows 2000.
3
What systems are affected by CVE-2005-3170?
CVE-2005-3170 affects Microsoft Windows 2000 with Service Pack 4.
4
What risk does CVE-2005-3170 pose?
CVE-2005-3170 poses a risk of certificate spoofing, potentially leading users to believe they are on trusted sites.
5
When was CVE-2005-3170 reported?
CVE-2005-3170 was reported in 2005.