CVE-2020-16863: Windows Remote Desktop Service Denial of Service Vulnerability

Overview

Severity
High (CVSS 7.5)
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
Category
Denial of Service
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2020-Oct
Released
2020-10-13
EPSS Score
16.62% (percentile: 94.9%)

Description

A denial of service vulnerability exists in Windows Remote Desktop Service when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the Remote Desktop Service on the target system to stop responding. To exploit this vulnerability, an attacker would need to run a specially crafted application against a server which provides Remote Desktop Service. The update addresses the vulnerability by correcting how Remote Desktop Service handles connection requests.

Affected Products (4)

Other

  • 10047
  • 10048
  • 10051
  • 10049

Security Updates (2)

Acknowledgments

VictorV (Tang Tianwen)

Revision History

  • 2020-10-13: Information published.