PT-2009-4387 · Microsoft · Terminal Services Client Activex Control+4

Published

2009-08-12

·

Updated

2023-12-07

·

CVE-2009-1929

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft Terminal Services Client ActiveX control versions 5.2 and 6.1
Description: A heap-based buffer overflow issue exists in the Microsoft Terminal Services Client ActiveX control. This allows remote attackers to execute arbitrary code via unspecified parameters to unknown methods. The issue affects Windows XP SP2, Vista SP1 or SP2, or Server 2008 Gold or SP2 with RDP 6.1, and Windows XP SP3 with versions 5.2 or 6.1.
Recommendations: For version 5.2, update to a newer version to mitigate the risk. For version 6.1, update to a newer version to mitigate the risk. As a temporary workaround, consider disabling the ActiveX control until a patch is available.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2009-1929

Affected Products

Terminal Services Client Activex Control
Rdp
Windows Server 2008
Windows Vista
Windows Xp