CVE-2007-2593
Last modified
CVE-2007-2593 is a vulnerability of currently unknown severity. The Terminal Server in Microsoft Windows 2003 Server, when using TLS, allows remote attackers to bypass SSL and self-signed certificate requirements, downgrade the server security, and possibly conduct man-in-the-middle attacks via unspecified vectors, as demonstrated using the Remote Desktop Protocol (RDP) 6.0 client. NOTE: a third party claims that the vendor may have fixed this in approximately 2006.. EPSS estimates a 9.45% chance of exploitation in the next 30 days.
Description
The Terminal Server in Microsoft Windows 2003 Server, when using TLS, allows remote attackers to bypass SSL and self-signed certificate requirements, downgrade the server security, and possibly conduct man-in-the-middle attacks via unspecified vectors, as demonstrated using the Remote Desktop Protocol (RDP) 6.0 client. NOTE: a third party claims that the vendor may have fixed this in approximately 2006.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Terminal Server | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-2593?
How severe is CVE-2007-2593?
How do I fix CVE-2007-2593?
Are you affected by CVE-2007-2593?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
