First published: Thu Oct 06 2005(Updated: )
Microsoft Windows 2000 before Update Rollup 1 for SP4 does not record the IP address of a Windows Terminal Services client in a security log event if the client connects successfully, which could make it easier for attackers to escape detection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2000 | =sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3176 is considered to have a medium severity rating due to the potential for undetected access by malicious users.
To mitigate CVE-2005-3176, it's essential to apply Update Rollup 1 for SP4 for Microsoft Windows 2000.
CVE-2005-3176 reduces the effectiveness of security logging by failing to record the IP address of successfully connected Windows Terminal Services clients.
CVE-2005-3176 affects Microsoft Windows 2000 SP4 prior to Update Rollup 1.
While CVE-2005-3176 is an older vulnerability, it remains relevant for legacy systems still running unpatched versions of Windows 2000.