PT-2002-2146 · Microsoft · Netmeeting
Published
2002-10-01
·
Updated
2016-10-18
·
CVE-2002-1150
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Microsoft NetMeeting versions 3.01 through SP2 (4.4.3396)
Description:
The issue allows attackers with physical access to hijack remote sessions by entering certain logoff or shutdown sequences, such as CTRL-ALT-DEL, and canceling out of the resulting user confirmation prompts. This can occur when the remote user is engaged in activities like editing a document.
Recommendations:
For Microsoft NetMeeting versions 3.01 through SP2 (4.4.3396), consider restricting physical access to the system to minimize the risk of exploitation. As a temporary workaround, implement additional authentication or authorization measures when remote sessions are initiated to reduce the likelihood of session hijacking.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netmeeting