|| Hotline : 800 2378 ||  To contact CERT-MU send e-mail on --> info[at]cert-mu.gov.mu ||  To report incident e-mail on --> incident[at]cert-mu.gov.mu || To report Vulnerabilities send e-mail on --> Vulnerability[at]cert-mu.gov.mu ||
    Constituency
    Authority
    Vol. 2, Feb 2012
    Vol. 1, Oct 2011
    World CERTs
    Email Abuse
 
 
Authorized to use CERT(TM) - CERT is a mark owned by Carnegie Mellon University
 
 
 
 
 
 
 
 
 
 
 
 


   
 

CERT-MU Vulnerability Note VN-2009-21

Microsoft Windows Remote Desktop Connection Remote Code Execution Vulnerabilities

Original Issue Date: August 13, 2009

Severity Rating: High

Affected Softwares

  • Microsoft Windows 2000 SP4
  • Microsoft Windows XP SP3
  • Microsoft Windows XP SP2
  • Microsoft Windows XP Professional x64 Edition SP2
  • Microsoft Windows Server 2003 SP2
  • Microsoft Windows Server 2003 for Itanium-based Systems with SP2
  • Microsoft Windows Vista SP
  • Microsoft Windows Vista SP1
  • Microsoft Windows Vista SP2
  • Microsoft Windows Vista x64 Edition
  • Microsoft Windows Server 2008 for 32-bit Systems SP2
  • Microsoft Windows Server 2008 for x64-based Systems SP2
  • Microsoft Windows Server 2008 for Itanium-based Systems
  • Macintosh OS X Systems using Microsoft Remote Desktop Connection Client for Mac version 2

Affected Component

  • RDP Versions 6.1, 6.0, 5.2, 5.1,5.0

Overview

Two remote code execution vulnerabilities have been in reported Microsoft Remote Desktop connection. An attacker can exploit these vulnerabilities by persuading a user of terminal services to connect to a malicious RDP (Remote Desktop Protocol) server or trick the user to visit a specially crafted website to exploit these vulnerabilities by getting them to click a link of an e-mail message or Instant Messenger message. Successful exploitation of this vulnerability results in remote execution of arbitrary code in the context of the logged-in-user.

If a user is logged on with administrative privileges, an attacker who successfully exploited this vulnerability could take complete control of an affected system.

Description

The Microsoft Remote Desktop Protocol (RDP) provides remote display and input capabilities over network connections for Windows-based applications running on a server.

 
 
News & Events
Safer Internet Day 2012
Computer Security Day 2011
Workshop on Cloud Security
Workshop on Mobile Security
Certificate Award Ceremony for Trainings in Information Security Management

  more...
 
Virus Alerts
RSS Feed
 
 
 

Last Updated 20-Jul-2011
Disclaimer Maintained & Hosted by NCB
This site is best viewed in 1024 x 768 resolution. Internet Explorer 6.0 +