CVE-2020-16896
published 2020-10-16CVE-2020-16896: An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially…
PriorityP182high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
10.46%
95.2th percentile
An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would need to run a specially crafted application against a server which provides Remote Desktop Protocol (RDP) services.
The update addresses the vulnerability by correcting how RDP handles connection requests.
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1607 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1709 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1709_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1803 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_arm64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_x64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1909 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_8.1 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012_r2 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unauthenticated or specially crafted RDP connection requests to Windows RDP servers, particularly where Network Level Authentication (NLA) is not enforced — exploitation requires an attacker to connect via RDP and send specially crafted requests. ↗
- →Alert on RDP (TCP/3389) connections originating from outside the enterprise perimeter, especially to servers exposing Remote Desktop Services without NLA. ↗
- →Exploitation results in unauthorized read access to the Windows RDP server process memory — monitor for anomalous process memory reads or information leakage from the RDP service process. ↗
- ·Network Level Authentication (NLA) must be enabled to block unauthenticated exploitation; without NLA, unauthenticated attackers can reach the vulnerable code path. ↗
- ·Exploitation is rated 'More Likely' for both latest and older software releases, increasing urgency for patching or mitigation deployment. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vulncheck7.5HIGH
vendor_msrc7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
vendor_msrc·2020-10-13·CVSS 7.5
CVE-2020-16896 [HIGH] Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
Description: An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.
To exploit this vulnerability, an attacker would need to run a specially crafted application against a server which provides Remote Desktop Protocol (RDP) services.
The update addresses the vulnerability by correcting how RDP handles connection requests.
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploite
GHSA
GHSA-rh34-6rgm-2g3c: An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends spe
ghsa_unreviewed·2022-05-24
CVE-2020-16896 [HIGH] CWE-200 GHSA-rh34-6rgm-2g3c: An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends spe
An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability'.
VulnCheck
Windows Remote Desktop Protocol (RDP) Information Disclosure
vulncheck·2020·CVSS 7.5
CVE-2020-16896 [HIGH] Windows Remote Desktop Protocol (RDP) Information Disclosure
Windows Remote Desktop Protocol (RDP) Information Disclosure
An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would need to run a specially crafted application against a server which provides Remote Desktop Protocol (RDP) services.The update addresses the vulnerability by correcting how RDP handles connection requests.
Affected: Microsoft Windows
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
No detection rules found.
No public exploits indexed.
Sentinelone
Egregor
blogs_sentinelone·2022-11-30
Egregor
How It Works The Singularity XDR Difference
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management
Trendmicro
Microsoft's Patch Tuesday update for October has a relatively smaller number of patches. After a few months where the number of bug fixes exceeded the 100-mark, October’s round of updates stood at 87,
blogs_trendmicro·2020-10-14·CVSS 7.5
[HIGH] Microsoft's Patch Tuesday update for October has a relatively smaller number of patches. After a few months where the number of bug fixes exceeded the 100-mark, October’s round of updates stood at 87,
# Smaller October Patch Tuesday Fixes TCP/IP, RDP Bugs
Microsoft's Patch Tuesday update for October has a relatively smaller number of patches. After a few months where the number of bug fixes exceeded the 100-mark, October’s round of updates stood at 87, containing fixes for eleven that were rated as Critical.
By: Trend Micro Research
2020/10/14
Read time: ( words)
Save to Folio
Microsoft's Patch Tuesday update for October has a relatively smaller number of patches. After a few months where the number of bug fixes exceeded the 100-mark, October’s round of updates stood at 87, containing fixes for eleven that were rated as Critical.
## Critical TCP/IP vulnerabilities lead the way
Two of the more notable vulnerabilities that were addressed involved TCP/IP. The first, CVE-2020-16898,
Sentinelone
Egregor
blogs_sentinelone
Egregor
# Egregor Ransomware: In-Depth Analysis, Detection, and Mitigation
## What Is Egregor Ransomware?
Egregor ransomware is part of the Sekhmet malware family that has been active since mid-September 2020. The ransomware operates by hacking into organizations, stealing sensitive user documents, encrypting data, and demanding a ransom to exchange encrypted documents. The Egregor ransomware has been used in several attacks against large organizations, including the French media company Le Monde and the Canadian government.
## What Does Egregor Ransomware Target?
Egregor ransomware targets organizations across all industries, with focus on healthcare, education, financial services, manufacturing and retail industries. Egregor is known to heavily target school districts and higher education in
2020-10-16
Published
Exploited in the wild