PT-2009-4387 · Microsoft · Terminal Services Client Activex Control+4
Published
2009-08-12
·
Updated
2023-12-07
·
CVE-2009-1929
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Microsoft Terminal Services Client ActiveX control versions 5.2 and 6.1
Description:
A heap-based buffer overflow issue exists in the Microsoft Terminal Services Client ActiveX control. This allows remote attackers to execute arbitrary code via unspecified parameters to unknown methods. The issue affects Windows XP SP2, Vista SP1 or SP2, or Server 2008 Gold or SP2 with RDP 6.1, and Windows XP SP3 with versions 5.2 or 6.1.
Recommendations:
For version 5.2, update to a newer version to mitigate the risk.
For version 6.1, update to a newer version to mitigate the risk.
As a temporary workaround, consider disabling the ActiveX control until a patch is available.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Terminal Services Client Activex Control
Rdp
Windows Server 2008
Windows Vista
Windows Xp