Rapid7 Vulnerability & Exploit Database

MS01-052: Invalid RDP Data Can Cause Terminal Service Failure

Back to Search

MS01-052: Invalid RDP Data Can Cause Terminal Service Failure

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
10/18/2001
Created
07/25/2018
Added
11/30/2004
Modified
07/30/2012

Description

Your system may require one or more security patches or hotfixes from Microsoft.

The implementation of the Remote Data Protocol (RDP) in the terminal service in Windows NT 4.0 and Windows 2000 does not correctly handle a particular series of data packets. If such a series of packets were received by an affected server, it would cause the server to fail. The server could be put back into normal service by rebooting it, but any work in progress at the time of the attack would be lost. It would not be necessary for an attacker to be able to start a session with an affected server in order to exploit this vulnerability, the only prerequisite would be the need to be able to send the correct series of packets to the RDP port on the server.

Solution(s)

  • install-microsoft-patch-7e590841d31c849d2c0a68a636c914de
  • install-microsoft-patch-98bf45b15be52bd4eda48793178e4bb6

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;