Microsoft Remote Desktop Protocol Security Feature Bypass Vulnerability
RISK: Medium Risk
TYPE: Operating Systems - Windows OS
A security feature bypass vulnerability exists in Remote Desktop Protocol (RDP) when RDP does not properly log failed logon attempts. The vulnerability could allow an attacker to bypass the audit logon security feature. The security feature bypass by itself does not allow arbitrary code execution. However an attacker could use this bypass vulnerability in conjunction with another vulnerability. The update addresses the vulnerability by correcting the way Remote Desktop Protocol handles authentication and logging.
Impact
- Security Restriction Bypass
System / Technologies affected
- Windows Vista
- Windows Server 2008
- Windows 7
- Windows Server 2008 R2
- Windows 8 and Windows 8.1
- Windows Server 2012 and Windows Server 2012 R2
- Windows RT and Windows RT 8.1
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
https://technet.microsoft.com/en-us/library/security/ms14-074.aspx
Vulnerability Identifier
Source
Related Link
Share with