I am new to Nessus and am trying to use Nessus 2.2.6 to scan a Windows XP machine.  It's right out of the box, no patches.  The scan does not catch anything.  If I run the scan on another XP machine I have, it picks up the following vulnerability:

Vulnerability microsoft-ds (445/tcp)
Synopsis :

Arbitrary code can be executed on the remote host.

Description :

The remote version of Windows contains a flaw in the Web Client service which
may allow an attacker to execute arbitrary code on the remote host.

To exploit this flaw, an attacker would need credentials to log into the
remote host.

Solution :

Microsoft has released a set of patches for Windows XP and 2003 :

http://www.microsoft.com/technet/security/bulletin/ms06-008.mspx

Risk factor :

Medium / CVSS Base Score : 6
(AV:R/AC:L/Au:R/C:C/A:C/I:C/B:N)
CVE : CVE-2006-0013
BID : 16636
Nessus ID : 20928

I think there would be numerous vulnerabilities on an unpatched Windows machine.  Is there a reason why the same set of plugins would see the vulnerability on one machine and not on the other?

Thanks,
Susan


Feel free to call! Free PC-to-PC calls. Low rates on PC-to-Phone. Get Yahoo! Messenger with Voice
_______________________________________________
Nessus mailing list
[email protected]
http://mail.nessus.org/mailman/listinfo/nessus

Reply via email to