PT-2023-2696 · Microsoft · Remote Desktop Client+2
CVE-2023-24905
·
Publicado
2023-05-09
·
Atualizado
2024-05-29
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows 10 version 22H2
Description
The issue exists due to insufficient input validation in the Remote Desktop Client of the Windows operating system. This allows an attacker to execute arbitrary code, potentially impacting the system. The vulnerability can be exploited by chaining DLL Hijacking and Format String techniques, enabling remote code execution on the Windows RDP Client.
Recommendations
For Windows 10 version 22H2, consider disabling the Remote Desktop Client until a patch is available to prevent potential exploitation. Restrict access to the Remote Desktop Client to minimize the risk of arbitrary code execution. Avoid using the Remote Desktop Client on devices with ARM architecture until the issue is resolved.
Correção
RCE
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Remote Desktop Client
Windows
Windows 10