Msrc Microsoft Remote Desktop vulnerabilities

5 known vulnerabilities affecting msrc/microsoft_remote_desktop.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH1MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2023-28290MEDIUMCVSS 5.32023-05-09
CVE-2023-28290 [MEDIUM] Microsoft Remote Desktop app for Windows Information Disclosure Vulnerability Microsoft Remote Desktop app for Windows Information Disclosure Vulnerability FAQ: How could an attacker exploit this vulnerability? When an Microsoft Remote Desktop app for Windows client connects to the server and the user saves the self-signed certificate, the serial number is used to compare the certificate for future use. An attacker could swap out a forged certificate with the same serial
msrc
CVE-2021-1669HIGHCVSS 8.82021-01-12
CVE-2021-1669 [HIGH] Windows Remote Desktop Security Feature Bypass Vulnerability Windows Remote Desktop Security Feature Bypass Vulnerability FAQ: How do I get the update for Microsoft Remote Desktop for Android? Tap the Google Play icon on your home screen. Swipe in from the left edge of the screen. Tap My apps & games. Tap the Update box next to the Remote Desktop app. Windows Remote Desktop: Windows Remote Desktop Microsoft: Microsoft Customer Action Required: Yes Impact: Security Fea
msrc
CVE-2019-1181CRITICALCVSS 9.82019-08-13
CVE-2019-1181 [CRITICAL] Remote Desktop Services Remote Code Execution Vulnerability Remote Desktop Services Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this
msrc
CVE-2019-1182CRITICALCVSS 9.82019-08-13
CVE-2019-1182 [CRITICAL] Remote Desktop Services Remote Code Execution Vulnerability Remote Desktop Services Remote Code Execution Vulnerability Description: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this
msrc
CVE-2019-1108MEDIUMCVSS 6.5Exploited2019-07-09
CVE-2019-1108 [MEDIUM] Remote Desktop Protocol Client Information Disclosure Vulnerability Remote Desktop Protocol Client Information Disclosure Vulnerability Description: An information disclosure vulnerability exists when the Windows RDP client improperly discloses the contents of its memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit this vulnerability, an attacker would have to connect remotely to an
msrc