CVE-2020-16896

5 documents5 sources
Severity
7.5HIGH
EPSS
10.6%
top 6.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 16
Latest updateMay 24

Description

An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would need to run a specially crafted application against a server which provides Remote Desktop Protocol (RDP) services. The update addresses the vulnerabili

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages21 packages

CVEListV5microsoft/windows_server_201610.0.0publication

Patches

🔴Vulnerability Details

3
GHSA
GHSA-rh34-6rgm-2g3c: An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends spe2022-05-24
CVEList
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability2020-10-16
VulnCheck
Windows Remote Desktop Protocol (RDP) Information Disclosure2020

📋Vendor Advisories

1
Microsoft
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability2020-10-13
CVE-2020-16896 (HIGH CVSS 7.5) | An information disclosure vulnerabi | cvebase.io