Vulnerabilities > CVE-2002-1256 - Unspecified vulnerability in Microsoft products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digital signing settings in an SMB session to force the data to be sent unsigned, then inject data into the session without detection, e.g. by modifying group policy information sent from a domain controller.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 11 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS02-070.NASL |
description | The remote version of Windows contains a flaw in the SMB signing implementation. SMB signing is used to sign each packets sent between a client and a server to protect them against man-in-the-middle attacks. If the Domain policy is configured to force usage of SMB signing, it is possible for an attacker to downgrade the communication to disable SMB signing and try to launch man-in-the-middle attacks. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11215 |
published | 2003-01-25 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11215 |
title | MS02-070: Flaw in SMB Signing Could Enable Group Policy to be Modified (329170) |
code |
|
Oval
accepted | 2005-10-19T05:47:00.000-04:00 | ||||||||
class | vulnerability | ||||||||
contributors |
| ||||||||
description | The SMB signing capability in the Server Message Block (SMB) protocol in Microsoft Windows 2000 and Windows XP allows attackers to disable the digital signing settings in an SMB session to force the data to be sent unsigned, then inject data into the session without detection, e.g. by modifying group policy information sent from a domain controller. | ||||||||
family | windows | ||||||||
id | oval:org.mitre.oval:def:277 | ||||||||
status | accepted | ||||||||
submitted | 2003-09-16T12:00:00.000-04:00 | ||||||||
title | SMB Session Digital Signature Sidestep | ||||||||
version | 65 |