Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2019-1489

Опубликовано: 10 дек. 2019
Источник: msrc
EPSS Низкий

Описание

Remote Desktop Protocol Information Disclosure Vulnerability

An information disclosure vulnerability exists when the Windows Remote Desktop Protocol (RDP) fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.

To exploit this vulnerability, an attacker would have to connect remotely to an affected system and run a specially crafted application.

FAQ

Why is there no update for this vulnerability?

Microsoft will not provide an update for this vulnerability because Windows XP is out of support. Microsoft strongly recommends upgrading to a supported version of Windows software.

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

N/A

Older Software Release

N/A

EPSS

Процентиль: 90%
0.06002
Низкий

Связанные уязвимости

CVSS3: 7.5
nvd
около 6 лет назад

An information disclosure vulnerability exists when the Windows Remote Desktop Protocol (RDP) fails to properly handle objects in memory, aka 'Remote Desktop Protocol Information Disclosure Vulnerability'.

github
больше 3 лет назад

An information disclosure vulnerability exists when the Windows Remote Desktop Protocol (RDP) fails to properly handle objects in memory, aka 'Remote Desktop Protocol Information Disclosure Vulnerability'.

CVSS3: 6.5
fstec
около 6 лет назад

Уязвимость реализации протокола RDP операционных систем Windows, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 90%
0.06002
Низкий