CNCVE编号:CNCVE-20010860 CVE编号:CAN-2001-0860 安全级别:中 漏洞中文描述: 在Windows 2000和XP中终端服务管理器MMC信任那些由客户端提供的客户端地址(IP地址)来代替从包头所获得的IP地址,因为这种方法允许客户端欺骗他们公共的IP地址,举例来说,通过一个Network Address Translation(NAT)就可以实现。 漏洞英文描述: Terminal Services Manager MMC in Windows 2000 and XP trusts the Client Address (IP address) that is provided by the client instead of obtaining it from the packet headers, which allows clients to spoof their public IP address, e.g. through a Network Address Translation(NAT). 漏洞参考: Reference: BUGTRAQ:20011114 Xato Advisory: Win2k/XP Terminal Services IP Spoofing Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100578220002083&w=2 系统类型: Win2000/NT 漏洞类型:设计错误