PT-2005-3998 · Microsoft · Windows 2000

Publicado

2005-10-06

·

Atualizado

2008-09-05

·

CVE-2005-3176

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Windows 2000 before Update Rollup 1 for SP4
Description The issue concerns a lack of logging in security events, specifically when a Windows Terminal Services client connects successfully. This omission could facilitate attackers evading detection, as their IP addresses are not recorded in the security log.
Recommendations For Microsoft Windows 2000 before Update Rollup 1 for SP4, apply Update Rollup 1 for SP4 to ensure that IP addresses of connecting clients are properly logged in security events.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3176

Produtos afetados

Windows 2000