Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Windows_2000 | Microsoft | * | * |
Windows_2003_server | Microsoft | enterprise (including) | enterprise (including) |
Windows_2003_server | Microsoft | r2 (including) | r2 (including) |
Windows_2003_server | Microsoft | standard (including) | standard (including) |
Windows_2003_server | Microsoft | web (including) | web (including) |
Windows_xp | Microsoft | * | * |