PT-2024-1149 · Microsoft · Windows+1

Mingjia Liu

+2

·

Published

2024-01-09

·

Updated

2024-05-29

·

CVE-2024-21307

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Remote Desktop Client versions prior to 1.2.5105
Description The issue is related to errors in synchronization when using a shared resource in the Remote Desktop Protocol (RDP) of the Windows operating system. This can allow a remote attacker to execute arbitrary code.
Recommendations For versions prior to 1.2.5105, update to version 1.2.5105 or later to resolve the issue. As a temporary workaround, consider restricting access to the Remote Desktop Protocol to minimize the risk of exploitation.

Fix

RCE

Use After Free

Race Condition

Weakness Enumeration

Related Identifiers

BDU:2024-00465
CVE-2024-21307

Affected Products

Remote Desktop Client
Windows