Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft Windows Remote Desktop Protocol Server Private Key Disclosure Vulnerability

The vulnerability presents itself because a private key that is used to sign the Terminal Server public key is hardcoded in a DLL.

This can allow the attacker to disclose the key and calculate a valid signature to carry out man in the middle attacks.

An attacker could therefore cause the client to connect to a server under their control and send the client a public key to which they possess the private key.







 

Privacy Statement
Copyright 2008, SecurityFocus