PC Tools - Essential tools for your PC | United States & Canada
Search
 
 
Features
 
 
Newsletter
 
Security Home > BackOffice Software

Invalid RDP Data can Cause Terminal Service Failure New

A security vulnerability exists in the terminal service of Windows 2000 and Windows NT 4.0 which could allow a malicious user to cause a denial of service attack by sending malformed data packets.

Issue

The implementation of the Remote Data Protocol (RDP) in the terminal service in Windows NT 4.0 and Windows 2000 does not correctly handle a particular series of data packets. If such a series of packets were received by an affected server, it would cause the server to fail. The server could be put back into normal service by rebooting it, but any work in progress at the time of the attack would be lost.

It would not be necessary for an attacker to be able to start a session with an affected server in order to exploit this vulnerability – the only prerequisite would be the need to be able to send the correct series of packets to the RDP port on the server.

Affected Products

  • Microsoft Windows NT 4.0 and Windows 2000

Solution

A software patch is available from the following locations:

Further Details

Source: Microsoft Corporation

Reference: Microsoft Corporation

Updated: October 22, 2001

>> Recommended Download - secure your PC from spyware, adware and malware now with Spyware Doctor <<

 
  Copyright © 1998-2010 PC Tools. All rights reserved. Privacy Policy | Legal Notice