Microsoft Windows Remote Desktop and Terminal Server Multiple Vulnerabilities
RISK: High Risk
TYPE: Operating Systems - Windows OS
Remote Desktop Protocol Vulnerability
A remote code execution vulnerability exists in the way that the Remote Desktop Protocol accesses an object in memory that has been improperly initialized or has been deleted. An attacker who successfully exploited this vulnerability could run abitrary code on the target system. An attacker could then install programs; view,change, or delete data; or create new accounts with full user rights.
Terminal Server Denial of Service Vulnerability
A denial of service vulnerability exists in the way that the Remote Desktop Protocol service processes packets. An attacker who successfully exploited this vulnerability could cause the target service to stop responding.
Impact
- Remote Code Execution
System / Technologies affected
- Windows XP
- Windows Server 2003
- Windows Vista
- Windows Server 2008
- Windows 7
- Windows Server 2008 R2
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Download location for patches:
http://technet.microsoft.com/en-us/security/bulletin/ms12-020
Vulnerability Identifier
Source
Related Link
Share with