CVE-2005-3176

Microsoft Windows 2000 <Update Rollup 1 for SP4 - Info Disclosure

Title source: llm
STIX 2.1

Description

Microsoft Windows 2000 before Update Rollup 1 for SP4 does not record the IP address of a Windows Terminal Services client in a security log event if the client connects successfully, which could make it easier for attackers to escape detection.

References (2)

Core 2
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/kb/891076
Patch, Vendor Advisory vendor-advisory x_refsource_mskb
http://support.microsoft.com/kb/900345

Scores

EPSS 0.0391
EPSS Percentile 89.3%

Details

Status published
Products (1)
microsoft/windows_2000
Published Oct 06, 2005
Tracked Since Feb 18, 2026