Executive Summary
Informations | |||
---|---|---|---|
Name | MS05-042 | First vendor Publication | N/A |
Vendor | Microsoft | Last vendor Modification | N/A |
Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:P/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 3.6 | Attack Range | Local |
Cvss Impact Score | 4.9 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Vulnerabilities in Kerberos Could Allow Denial of Service, Information Disclosure, and Spoofing (899587) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:100095 | |||
Oval ID: | oval:org.mitre.oval:def:100095 | ||
Title: | Windows 2000 Kerberos Message DoS Vulnerability | ||
Description: | Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2005-1981 | Version: | 6 |
Platform(s): | Microsoft Windows 2000 | Product(s): | |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:100096 | |||
Oval ID: | oval:org.mitre.oval:def:100096 | ||
Title: | Windows 2000 PKINIT Information Disclosure Vulnerability | ||
Description: | Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2005-1982 | Version: | 6 |
Platform(s): | Microsoft Windows 2000 | Product(s): | |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:100097 | |||
Oval ID: | oval:org.mitre.oval:def:100097 | ||
Title: | Windows XP,SP1 (32-bit) Kerberos Message DoS Vulnerability | ||
Description: | Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2005-1981 | Version: | 5 |
Platform(s): | Microsoft Windows XP | Product(s): | |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:100098 | |||
Oval ID: | oval:org.mitre.oval:def:100098 | ||
Title: | Windows XP,SP1 (32-bit) PKINIT Information Disclosure Vulnerability | ||
Description: | Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2005-1982 | Version: | 5 |
Platform(s): | Microsoft Windows XP | Product(s): | |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:100099 | |||
Oval ID: | oval:org.mitre.oval:def:100099 | ||
Title: | Windows XP,SP2 Kerberos Message DoS Vulnerability | ||
Description: | Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2005-1981 | Version: | 6 |
Platform(s): | Microsoft Windows XP | Product(s): | |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:100100 | |||
Oval ID: | oval:org.mitre.oval:def:100100 | ||
Title: | Windows XP,SP2 PKINIT Information Disclosure Vulnerability | ||
Description: | Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2005-1982 | Version: | 6 |
Platform(s): | Microsoft Windows XP | Product(s): | |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:100101 | |||
Oval ID: | oval:org.mitre.oval:def:100101 | ||
Title: | Windows XP,SP1 (64-bit) Kerberos Message DoS Vulnerability | ||
Description: | Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2005-1981 | Version: | 5 |
Platform(s): | Microsoft Windows XP | Product(s): | |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:100102 | |||
Oval ID: | oval:org.mitre.oval:def:100102 | ||
Title: | Windows XP,SP1 (64-bit) PKINIT Information Disclosure Vulnerability | ||
Description: | Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2005-1982 | Version: | 5 |
Platform(s): | Microsoft Windows XP | Product(s): | |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:100103 | |||
Oval ID: | oval:org.mitre.oval:def:100103 | ||
Title: | Server 2003 Kerberos Message DoS Vulnerability | ||
Description: | Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2005-1981 | Version: | 6 |
Platform(s): | Microsoft Windows Server 2003 | Product(s): | |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:100104 | |||
Oval ID: | oval:org.mitre.oval:def:100104 | ||
Title: | Server 2003 PKINIT Information Disclosure Vulnerability | ||
Description: | Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2005-1982 | Version: | 6 |
Platform(s): | Microsoft Windows Server 2003 | Product(s): | |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:100105 | |||
Oval ID: | oval:org.mitre.oval:def:100105 | ||
Title: | Server 2003,SP1 Kerberos Message DoS Vulnerability | ||
Description: | Unknown vulnerability in Microsoft Windows 2000 Server and Windows Server 2003 domain controllers allows remote authenticated users to cause a denial of service (system crash) via a crafted Kerberos message. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2005-1981 | Version: | 5 |
Platform(s): | Microsoft Windows Server 2003 | Product(s): | |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:100106 | |||
Oval ID: | oval:org.mitre.oval:def:100106 | ||
Title: | Server 2003,SP1 PKINIT Information Disclosure Vulnerability | ||
Description: | Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2005-1982 | Version: | 5 |
Platform(s): | Microsoft Windows Server 2003 | Product(s): | |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
18609 | Microsoft Windows Kerberos PKINIT Domain Controller Spoofing Windows contains a flaw that may lead to an unauthorized information disclosure. Â The issue is triggered when an attacker inserts himself between a client and domain controller and exploit a design flaw in PKINT to spoof the domain controller, which will disclose session information resulting in a loss of confidentiality. |
18608 | Microsoft Windows Kerberos Crafted Packet Remote DoS Windows contains a flaw that may allow a remote denial of service. The issue is triggered when an attacker sends a specially crafted Kerberos message to a machine functioning as a domain controller, and will result in loss of availability for the platform. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2005-08-09 | Name : It is possible to crash the remote service or disclose information. File : smb_nt_ms05-042.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:45:15 |
|