First published: Fri May 05 2006(Updated: )
The MS-Logon authentication scheme in UltraVNC (aka Ultr@VNC) 1.0.1 uses weak encryption (XOR) for challenge/response, which allows remote attackers to gain privileges by sniffing and decrypting passwords.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
UltraVNC UltraVNC | =1.0.1 | |
UltraVNC | =1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2206 is considered to have a high severity due to the use of weak encryption in the MS-Logon authentication scheme.
To fix CVE-2006-2206, users should upgrade to a newer version of UltraVNC that does not utilize weak encryption.
CVE-2006-2206 can be exploited by remote attackers who can sniff network traffic to decrypt user passwords.
CVE-2006-2206 specifically affects UltraVNC version 1.0.1.
CVE-2006-2206 impacts user security by allowing unauthorized privilege escalation through compromised passwords.