CVE-2017-6356Medium

CVE-2017-6356 Information Disclosure in Terminal Server Agent

Published
March 15, 2017
Last Modified
March 15, 2017

🔗 CVE IDs covered (1)

📋 Description

An information disclosure vulnerability exists in the Terminal Server (TS) agent. Session information may be disclosed due to insecure permissions (WINAGENT-43 / CVE-2017-6356). The information disclosure is limited to session information. This issue affects TS agent 6.0, TS agent 7.0, and TS agent 8.0.

🎯 Affected products1

  • Terminal Server Agent

✅ Remediation

TS agent 8.0.1 and later releases. We recommend customers use custom certificates when using the TS agent. Further details on using customer certificates can be reviewed at: https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/user-id/configure-user-mapping-for-terminal-server-users.html Workarounds and mitigations: TS agent is fully backwards compatible with all currently supported versions of PAN-OS software. Customers using TS agents 6.0 and 7.0 can use TS agent 8.0.1.

🔗 References (1)