CVE-2002-0863

Microsoft Windows <2000/XP - Info Disclosure

Title source: llm
STIX 2.1

Description

Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Encryption in RDP Protocol."

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5711
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10122.php
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/865833
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=103235960119404&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5712
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=103236181522253&w=2
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10121.php
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A199

Scores

EPSS 0.2198
EPSS Percentile 97.4%

Details

Status published
Products (5)
microsoft/.net_windows_server beta3
microsoft/windows_2000 (4 CPE variants)
microsoft/windows_2000_terminal_services (4 CPE variants)
microsoft/windows_nt 4.0 (8 CPE variants)
microsoft/windows_xp (5 CPE variants)
Published Oct 11, 2002
Tracked Since Feb 18, 2026