Microsoft RDP ActiveX Control Remote Code Execution Vulnerability
Last Update Date:
10 Apr 2013 12:21
Release Date:
10 Apr 2013
5087
Views
RISK: High Risk
TYPE: Clients - Productivity Products
A remote code execution vulnerability exists when the Remote Desktop ActiveX control, mstscax.dll, attempts to access an object in memory that has been deleted. An attacker could exploit the vulnerability by convincing the user to visit a specially crafted webpage. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.
Impact
- Remote Code Execution
System / Technologies affected
- Remote Desktop Connection 6.1 Client
- Remote Desktop Connection 7.0 Client
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
http://technet.microsoft.com/en-us/security/bulletin/MS13-029
Vulnerability Identifier
Source
Related Link
Share with