PT-2009-4388 · Microsoft · Windows

Published

2009-08-12

·

Updated

2023-12-07

·

CVE-2009-1930

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft Windows versions prior to the fixed version
Description: The issue allows remote Telnet servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user. This is related to a credential reflection issue.
Recommendations: For Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2, update to a version that includes the fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2009-1930

Affected Products

Windows