CVE-2001-0860 Information

Description

Terminal Services Manager MMC in Windows 2000 and XP trusts the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers which allows clients to spoof their public IP address e.g. through a Network Address Translation (NAT).

Reference

http://marc.info/?l=bugtraq&m=100578220002083&w=2 http://www.securityfocus.com/bid/3541 https://exchange.xforce.ibmcloud.com/vulnerabilities/7538

Share on: