CVE-2016-0019Microsoft Windows 10 vulnerability

CWE-2546 documents5 sources
Severity
8.1HIGHNVD
EPSS
9.9%
top 6.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13
Latest updateMay 14

Description

The Remote Desktop Protocol (RDP) service implementation in Microsoft Windows 10 Gold and 1511 allows remote attackers to bypass intended access restrictions and establish sessions for blank-password accounts via a modified RDP client, aka "Windows Remote Desktop Protocol Security Bypass Vulnerability."

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

🔴Vulnerability Details

1
GHSA
GHSA-g267-2c4w-9f6x: The Remote Desktop Protocol (RDP) service implementation in Microsoft Windows 10 Gold and 1511 allows remote attackers to bypass intended access restr2022-05-14

📋Vendor Advisories

2
VMware
VMware Workstation and Fusion updates address critical out-of-bounds memory access vulnerability2016-11-13
Microsoft
CVE-2016-0019: Impact: Security Feature Bypass Exploit Status: Publicly Disclosed:No;Exploited:No2016-01-12

🕵️Threat Intelligence

2
Talos
Microsoft Patch Tuesday - January 20162016-01-12
Talos
Microsoft Patch Tuesday - January 20162016-01-12