CVE-2022-24503
published 2022-03-09CVE-2022-24503: Remote Desktop Protocol Client Information Disclosure Vulnerability
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
2.27%
81.1th percentile
Remote Desktop Protocol Client Information Disclosure Vulnerability
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | remote_desktop_client | < 1.2.2925 | 1.2.2925 |
| microsoft | remote_desktop_client_for_windows_desktop | >= 1.2.0.0 < 1.2.2925.0 | 1.2.2925.0 |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19235 | 10.0.10240.19235 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5006 | 10.0.14393.5006 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.2686 | 10.0.17763.2686 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.2686 | 10.0.17763.2686 |
| microsoft | windows_10_version_1909 | >= 10.0.0 < 10.0.18363.2158 | 10.0.18363.2158 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1586 | 10.0.19042.1586 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1586 | 10.0.19043.1586 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.1586 | 10.0.19044.1586 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.556 | 10.0.22000.556 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.25898 | 6.1.7601.25898 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.25898 | 6.1.7601.25898 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20303 | 6.3.9600.20303 |
| microsoft | windows_server | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.25898 | 6.1.7601.25898 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.23645 | 6.2.9200.23645 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_msrc5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Remote Desktop Protocol Client Information Disclosure Vulnerability
vendor_msrc·2022-03-08·CVSS 5.4
CVE-2022-24503 [MEDIUM] Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability
FAQ: What type of information could be disclosed by this vulnerability?
An attacker who successfully exploited this vulnerability could potentially read small portions of heap memory.
Windows Remote Desktop: Windows Remote Desktop
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Information Disclosure
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5011503
Reference: https://support.microsoft.com/help/5011503
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5011485
Reference: https://support.microsoft.co
GHSA
GHSA-fxhj-vjvm-j527: Remote Desktop Protocol Client Information Disclosure Vulnerability
ghsa_unreviewed·2022-03-10
CVE-2022-24503 [MEDIUM] CWE-668 GHSA-fxhj-vjvm-j527: Remote Desktop Protocol Client Information Disclosure Vulnerability
Remote Desktop Protocol Client Information Disclosure Vulnerability.
No detection rules found.
No public exploits indexed.
Krebs
Microsoft Patch Tuesday, March 2022 Edition
blogs_krebs·2022-03-09·CVSS 8.8
[HIGH] Microsoft Patch Tuesday, March 2022 Edition
Microsoft on Tuesday released software updates to plug at least 70 security holes in its Windows operating systems and related software. For the second month running, there are no scary zero-day threats looming for Windows users, and relatively few “critical” fixes. And yet we know from experience that attackers are already trying to work out how to turn these patches into a roadmap for exploiting the flaws they fix. Here’s a look at the security weaknesses Microsoft says are most likely to be targeted first.
Greg Wiseman , product manager at Rapid7 , notes that three vulnerabilities fixed this month have been previously disclosed, potentially giving attackers a head start in working out how to exploit them. Those include remote code execution bugs CVE-2022-24512 , affecting .NET and Visu
Krebs
Microsoft Patch Tuesday, March 2022 Edition
blogs_krebs·2022-03-09·CVSS 8.8
[HIGH] Microsoft Patch Tuesday, March 2022 Edition
Microsoft on Tuesday released software updates to plug at least 70 security holes in its Windows operating systems and related software. For the second month running, there are no scary zero-day threats looming for Windows users, and relatively few “critical” fixes. And yet we know from experience that attackers are already trying to work out how to turn these patches into a roadmap for exploiting the flaws they fix. Here’s a look at the security weaknesses Microsoft says are most likely to be targeted first.
Greg Wiseman, product manager at Rapid7, notes that three vulnerabilities fixed this month have been previously disclosed, potentially giving attackers a head start in working out how to exploit them. Those include remote code execution bugs CVE-2022-24512, affecting .NET and Visual
2022-03-09
Published