I performed a openVAS scan on a Windows Server 2008 R2
and got a report for a high threat level vulnerability called Microsoft RDP Server Private Key Information Disclosure Vulnerability
. An remote attacker could perform a man-in-the-middle
attack to gain access to a RDP session.
Affected Software is Microsoft RDP 5.2 and below.
My server uses RDP 7.1, is this alarm a false alarm?
Security Advisor Pages say: Solution Status Unpatched, No remedy...
References
http://secunia.com/advisories/15605/
http://xforce.iss.net/xforce/xfdb/21954/
http://www.oxid.it/downloads/rdp-gbu.pdf
CVE: CVE-2005-1794
BID:13818