CVE-2019-1290 — Microsoft Windows vulnerability
14 documents6 sources
Severity
8.8HIGHNVD
EPSS
30.3%
top 3.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 11
Latest updateMay 24
Description
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0787, CVE-2019-0788, CVE-2019-1291.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages23 packages
Patches
🔴Vulnerability Details
4GHSA▶
GHSA-3mc8-g687-m3cf: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Clie↗2022-05-24
GHSA▶
GHSA-57q3-7fwg-5h3g: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Clie↗2022-05-24
GHSA▶
GHSA-jgwx-vv8h-22r9: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Clie↗2022-05-24
GHSA▶
GHSA-r5xj-829m-j295: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Clie↗2022-05-24