Skip to main content

Microsoft RDP ActiveX Control Remote Code Execution Vulnerability

Last Update Date: 10 Apr 2013 12:21 Release Date: 10 Apr 2013 4299 Views

RISK: High Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

A remote code execution vulnerability exists when the Remote Desktop ActiveX control, mstscax.dll, attempts to access an object in memory that has been deleted. An attacker could exploit the vulnerability by convincing the user to visit a specially crafted webpage. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user.


Impact

  • Remote Code Execution

System / Technologies affected

  • Remote Desktop Connection 6.1 Client
  • Remote Desktop Connection 7.0 Client

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link