PT-2023-2696 · Microsoft · Remote Desktop Client+2

CVE-2023-24905

·

Publicado

2023-05-09

·

Atualizado

2024-05-29

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows 10 version 22H2
Description The issue exists due to insufficient input validation in the Remote Desktop Client of the Windows operating system. This allows an attacker to execute arbitrary code, potentially impacting the system. The vulnerability can be exploited by chaining DLL Hijacking and Format String techniques, enabling remote code execution on the Windows RDP Client.
Recommendations For Windows 10 version 22H2, consider disabling the Remote Desktop Client until a patch is available to prevent potential exploitation. Restrict access to the Remote Desktop Client to minimize the risk of arbitrary code execution. Avoid using the Remote Desktop Client on devices with ARM architecture until the issue is resolved.

Correção

RCE

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-02541
CVE-2023-24905

Produtos afetados

Remote Desktop Client
Windows
Windows 10