PT-2016-1044 · Microsoft · Windows 10+1

Published

2016-01-12

·

Updated

2018-10-30

·

CVE-2016-0019

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows 10 versions Gold and 1511
Description The issue is related to a security feature bypass in the Remote Desktop Protocol (RDP) service implementation, allowing remote attackers to bypass intended access restrictions. This can enable attackers to establish sessions for accounts with blank passwords via a modified RDP client. The vulnerability is caused by errors in security settings, which can be exploited by a remote attacker to bypass existing access restrictions or establish a connection for an account with a blank password.
Recommendations For Microsoft Windows 10 versions Gold and 1511, consider disabling the RDP service until a patch is available to prevent remote logon to accounts with no passwords set. As a temporary workaround, restrict access to accounts with blank passwords to minimize the risk of exploitation. Avoid using blank passwords for accounts to prevent potential exploitation of this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00111
CVE-2016-0019

Affected Products

Windows 10
Windows