CVE-2016-0190High

Remote Desktop Protocol Drive Redirection Information Disclosure Vulnerability

Published
May 10, 2016
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

An information disclosure vulnerability exists in Microsoft Windows when a USB disk mounted over Remote Desktop Protocol (RDP) via Microsoft RemoteFX is not correctly tied to the session of the mounting user. An attacker who successfully exploited this vulnerability could obtain access to file and directory information on the mounting user’s USB disk. This update addresses the vulnerability by ensuring that access to USB disks over RDP is correctly enforced to prevent non-mounting session access.

🎯 Affected products4

  • Windows Server 2012
  • Windows Server 2012 (Server Core installation)
  • Windows Server 2012 R2
  • Windows Server 2012 R2 (Server Core installation)

✅ Remediation

KB3155784 (Security Update)

🔗 References (2)