cbcvebase.
CVE-2020-0655
published 2020-02-11

CVE-2020-0655: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an authenticated attacker abuses…

PriorityP262high8CVSS 3.1
AVNACLPRLUIRSUCHIHAH
EPSS
65.69%
99.2th percentile
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

Affected

69 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_version_1903_for_32-bit_systems

Detection & IOCsextracted from sources · hover to see the quote

filenamemstscax.dll
filenameEvil.bat
processCFormatDataPacker::ValidateFilePaths
  • CVE-2020-0655 is exploited via clipboard redirection abuse in Remote Desktop Services; monitor RDP sessions for unexpected file drop activity via clipboard (FileGroupDescriptorW) that results in files written outside intended directories.
  • Monitor for file creation events triggered by mstscax.dll (the RDP client ActiveX component) that write files outside expected user directories, which may indicate exploitation of the path-traversal via clipboard redirection.
  • ·Exploitation requires the attacker to have already compromised a system running Remote Desktop Services and then wait for a victim to connect; it is not a zero-interaction remote exploit.
  • ·Microsoft's patch for CVE-2020-0655 only adds a workaround inside mstscax.dll and does not fix the underlying PathCchCanonicalize bypass; the core path-traversal issue via '/' separators remains unaddressed at the API level.

CVSS provenance

nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
vendor_msrc8.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.