Vulnerabilities > CVE-2014-0296 - Cryptographic Issues vulnerability in Microsoft products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The Remote Desktop Protocol (RDP) implementation in Microsoft Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not properly encrypt sessions, which makes it easier for man-in-the-middle attackers to obtain sensitive information by sniffing the network or modify session content by sending crafted RDP packets, aka "RDP MAC Vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 5 |
Common Weakness Enumeration (CWE)
Common Attack Pattern Enumeration and Classification (CAPEC)
- Signature Spoofing by Key Recreation An attacker obtains an authoritative or reputable signer's private signature key by exploiting a cryptographic weakness in the signature algorithm or pseudorandom number generation and then uses this key to forge signatures from the original signer to mislead a victim into performing actions that benefit the attacker.
Msbulletin
bulletin_id | MS14-030 |
bulletin_url | |
date | 2014-06-10T00:00:00 |
impact | Tampering |
knowledgebase_id | 2969259 |
knowledgebase_url | |
severity | Important |
title | Vulnerability in Remote Desktop Could Allow Tampering |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS14-030.NASL |
description | The remote Windows host is affected by a tampering vulnerability due to an encryption weakness in the Remote Desktop Protocol (RDP). An attacker could exploit this vulnerability to modify the traffic content of an active RDP session. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 74422 |
published | 2014-06-11 |
reporter | This script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/74422 |
title | MS14-030: Vulnerability in Remote Desktop Could Allow Tampering (2969259) |
code |
|
References
- http://blogs.technet.com/b/srd/archive/2014/06/10/assessing-risk-for-the-june-2014-security-updates.aspx
- http://blogs.technet.com/b/srd/archive/2014/06/10/assessing-risk-for-the-june-2014-security-updates.aspx
- http://secunia.com/advisories/58524
- http://secunia.com/advisories/58524
- http://www.securityfocus.com/bid/67865
- http://www.securityfocus.com/bid/67865
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-030
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2014/ms14-030