cbcvebase.
CVE-2011-0029
published 2011-03-09

CVE-2011-0029: Untrusted search path vulnerability in the client in Microsoft Remote Desktop Connection 5.2, 6.0, 6.1, and 7.0 allows local users to gain privileges via a…

PriorityP333high7.4CVSS 3.1
AVLACHPRNUINSUCHIHAH
EPSS
7.16%
93.6th percentile
Untrusted search path vulnerability in the client in Microsoft Remote Desktop Connection 5.2, 6.0, 6.1, and 7.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .rdp file, aka "Remote Desktop Insecure Library Loading Vulnerability."

Affected

5 ranges
VendorProductVersion rangeFixed in
microsoftremote_desktop_connection_client
microsoftremote_desktop_connection_client
microsoftremote_desktop_connection_client
microsoftremote_desktop_connection_client
microsoftwindows_server_2008

CVSS provenance

nvdv3.17.4HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.