|
Microsoft Windows XP Remote Desktop Plaintext Username Vulnerability
Microsoft Windows XP Remote Desktop transmits user account names in plain text over the network when a connection is initiated. The account name sent is not necessarily the user account name on the remote machine; it is the most recent user account used by the remote desktop client. A sniffer could potentially capture traffic on a network and discover user account names, especially when repeated connections are being made to a particular machine from Remote Desktop clients. |
|
|
Privacy Statement |