Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/CVEDB/PoC-List
- https://github.com/CVEDB/awesome-cve-repo
- https://github.com/Farrhouq/Inpt-report
- https://github.com/InitRoot/CVE-2005-1794Scanner
- https://github.com/Ressurect0/fluffyLogic
- https://github.com/anvithalolla/Tesla_PenTest