Remote Desktop Client Remote Code Execution Vulnerability
🔗 CVE IDs covered (1)
📋 Description
A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server. An attacker who successfully exploited this vulnerability could execute arbitrary code on the computer of the connecting client. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would need to have control of a server and then convince a user to connect to it. An attacker would have no way of forcing a user to connect to the malicious server, they would need to trick the user into connecting via social engineering, DNS poisoning or using a Man in the Middle (MITM) technique. An attacker could also compromise a legitimate server, host malicious code on it, and wait for the user to connect. The update addresses the vulnerability by correcting how the Windows Remote Desktop Client handles connection requests.
🎯 Affected products21
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 Version 1607 for x64-based Systems
- Windows 10 Version 1703 for 32-bit Systems
- Windows 10 Version 1703 for x64-based Systems
- Windows 10 Version 1709 for 32-bit Systems
- Windows 10 Version 1709 for ARM64-based Systems
- Windows 10 Version 1709 for x64-based Systems
- Windows 10 Version 1803 for 32-bit Systems
- Windows 10 Version 1803 for ARM64-based Systems
- Windows 10 Version 1803 for x64-based Systems
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for ARM64-based Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 1903 for 32-bit Systems
- Windows 10 Version 1903 for ARM64-based Systems
- Windows 10 Version 1903 for x64-based Systems
- Windows 10 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 8.1 for 32-bit systems
- Windows 8.1 for x64-based systems
- Windows RT 8.1
✅ Remediation
KB4516068 (Security Update) KB4516058 (Security Update) KB4512578 (Security Update) KB4516066 (Security Update) KB4516070 (Security Update) KB4516044 (Security Update) KB4516067 (Monthly Rollup) KB4516064 (Security Only) KB4515384 (Security Update)
🔗 References (20)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2019-0788
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4516068
- referencehttps://support.microsoft.com/help/4516068
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4516058
- referencehttps://support.microsoft.com/help/4516058
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4512578
- referencehttps://support.microsoft.com/help/4512578
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4516066
- referencehttps://support.microsoft.com/help/4516066
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4516070
- referencehttps://support.microsoft.com/help/4516070
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4516044
- referencehttps://support.microsoft.com/help/4516044
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4516067
- referencehttps://support.microsoft.com/help/4516067
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4516064
- referencehttps://support.microsoft.com/help/4516064
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4515384
- referencehttps://support.microsoft.com/help/4515384
- referencehttps://support.microsoft.com/en-us/help/4515384