cbcvebase.
CVE-2020-0611
published 2020-01-14

CVE-2020-0611: A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote…

PriorityP181high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
8.08%
94.2th percentile
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.

Affected

63 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_version_1903_for_32-bit_systems

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2020-0611 is exploited when a user connects to a malicious RDP server; monitor for outbound RDP connections to untrusted/external servers, especially those initiated via social engineering, DNS poisoning, or MITM techniques.
  • An attacker could also compromise a legitimate RDP server and host malicious code on it; monitor for unexpected code execution or new account creation following RDP client connections.
  • Successful exploitation allows arbitrary code execution on the connecting client, including installing programs, modifying/deleting data, or creating new accounts with full user rights; alert on new privileged account creation or unexpected process spawning from RDP client processes.
  • ·Exploitation requires user interaction — the victim must initiate an RDP connection to the attacker-controlled server; no known in-the-wild exploitation or public exploit code was available at time of disclosure.
  • ·The vulnerability is in the Windows Remote Desktop Client (not the server/gateway); affected systems span Windows 7, 8, 10 and Windows Server 2008, 2012, 2016, 2019.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
vulncheck7.5HIGH
vendor_msrc7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.