PT-2000-1757 · Microsoft · Windows 2000
Publicado
2000-11-14
·
Atualizado
2018-10-12
·
CVE-2000-0834
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Windows 2000
Description
The issue concerns the Windows 2000 telnet client, which attempts to perform NTLM authentication by default. This allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to a malicious server.
Recommendations
For Windows 2000, consider disabling NTLM authentication for the telnet client as a temporary workaround until a patch is available. Restrict access to telnet services to minimize the risk of exploitation. Avoid using the telnet client to connect to untrusted servers until the issue is resolved.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Windows 2000