PT-2005-3992 · Microsoft · Windows 2000

CVE-2005-3170

·

Publicado

2005-10-06

·

Atualizado

2024-12-05

CVSS v3.1

5.0

Média

VetorAV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Microsoft Windows 2000 versions prior to Update Rollup 1 for SP4
Description The issue concerns the LDAP client accepting certificates using LDAPS even when the Certificate Authority (CA) is not trusted. This could allow attackers to trick users into believing they are accessing a trusted site.
Recommendations For Microsoft Windows 2000 versions prior to Update Rollup 1 for SP4, apply Update Rollup 1 for SP4 to resolve the issue. As a temporary workaround, consider restricting the use of LDAPS connections to trusted Certificate Authorities (CAs) until the update is applied.

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2005-3170

Produtos afetados

Windows 2000