PC Tools - Essential tools for your PC
Search
 
 
Features
 
 
Newsletter
 
Security Home > Windows NT, 2000 & XP > Windows 2000

Invalid RDP Data Vulnerability New

A security vulnerability exists affecting Microsoft® Windows® 2000 terminal servers which could allow an attacker to cause an affected server to fail.

Issue

The implementation of the Remote Data Protocol (RDP) in Windows 2000 Terminal Service does not correctly handle a particular series of data packets. If such a series of packets were received by an affected server, it would cause the server to fail. The server could be put back into normal service by rebooting it, but any work in progress at the time of the attack would be lost.

It would not be necessary for an attacker to be able to start a session with an affected server in order to exploit this vulnerability – he would only need the ability to send the correct series of packets to the RDP port on the server. The specific sequence of data packets involved in this vulnerability cannot be generated as part of a legitimate terminal server session. Windows NT 4.0 terminal servers are not affected by this vulnerability.

Affected Products

  • Windows 2000 Server and Advanced Server

Download

Patch: http://www.microsoft.com/Downloads/Release.asp?ReleaseID=27500

Further Details

Source: Microsoft Corporation

Reference: Microsoft Corporation

Updated: January 31, 2001

>> Recommended Download - secure your PC from spyware, adware and malware now with Spyware Doctor <<

 
  Copyright © 1998-2008 PC Tools. All rights Reserved. Privacy Policy | Legal Notice 


Are you looking for Mac security software?
PC Tools now offers iAntiVirus, a free antivirus product for Mac OS X. Please click below to learn more.

Tell me more No, thanks

Remember my answer