A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the RDP service on the target system to stop responding. To exploit this vulnerability, an attacker would need to run a specially crafted application against a server which provides Remote Desktop Protocol (RDP) services. The update addresses the vulnerability by correcting how RDP handles connection requests.
Existe una vulnerabilidad de denegación de servicio en Remote Desktop Protocol (RDP) cuando un atacante se conecta al sistema de destino mediante RDP y envía peticiones especialmente diseñadas, también se conoce como "Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability".
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | NONE |
| Availability Impact | HIGH |
AV:N/AC:L/Au:N/C:N/I:N/A:P
| Access Vector | NETWORK |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | NONE |
| Integrity Impact | NONE |
| Availability Impact | PARTIAL |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
NVD-CWE-noinfo
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| microsoft | windows_10 | 1803 | <built-in method update of dict object at 0x7e60bbd63480> | Operating System |
| microsoft | windows_10 | 1809 | <built-in method update of dict object at 0x7e6110c981c0> | Operating System |
| microsoft | windows_10 | 1903 | <built-in method update of dict object at 0x7e60baa08740> | Operating System |
| microsoft | windows_server_2016 | 1803 | <built-in method update of dict object at 0x7e6111c1ddc0> | Operating System |
| microsoft | windows_server_2016 | 1903 | <built-in method update of dict object at 0x7e60bbd62a80> | Operating System |
| microsoft | windows_server_2019 | - | <built-in method update of dict object at 0x7e60bbd61500> | Operating System |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_10:1809:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_10:1903:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_server_2016:1803:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_server_2016:1903:*:*:*:*:*:*:* |
| Yes | cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:* |