PT-2000-1757 · Microsoft · Windows 2000

Publicado

2000-11-14

·

Atualizado

2018-10-12

·

CVE-2000-0834

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Windows 2000
Description The issue concerns the Windows 2000 telnet client, which attempts to perform NTLM authentication by default. This allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to a malicious server.
Recommendations For Windows 2000, consider disabling NTLM authentication for the telnet client as a temporary workaround until a patch is available. Restrict access to telnet services to minimize the risk of exploitation. Avoid using the telnet client to connect to untrusted servers until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2000-0834

Produtos afetados

Windows 2000