CVE-2021-1669: Windows Remote Desktop Security Feature Bypass Vulnerability
Overview
- Severity
- High (CVSS 8.8)
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Security Feature Bypass
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2021-Jan
- Released
- 2021-01-12
- Last Updated
- 2021-12-14
- EPSS Score
- 7.22% (percentile: 91.6%)
FAQ
How do I get the update for Microsoft Remote Desktop for Android?
Tap the Google Play icon on your home screen.
Swipe in from the left edge of the screen.
Tap My apps & games.
Tap the Update box next to the Remote Desktop app.
Affected Products (27)
Windows
- Windows 10 Version 20H2 for 32-bit Systems
- Windows 10 Version 20H2 for ARM64-based Systems
- Windows Server, version 20H2 (Server Core Installation)
- Windows 10 Version 1803 for 32-bit Systems
- Windows 10 Version 1803 for x64-based Systems
- Windows 10 Version 1803 for ARM64-based Systems
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 1809 for ARM64-based Systems
- Windows Server 2019
- Windows 10 Version 1909 for 32-bit Systems
- Windows 10 Version 1909 for x64-based Systems
- Windows 10 Version 1909 for ARM64-based Systems
- Windows Server, version 1909 (Server Core installation)
- Windows 10 Version 2004 for 32-bit Systems
- Windows 10 Version 2004 for ARM64-based Systems
- Windows 10 Version 2004 for x64-based Systems
- Windows Server, version 2004 (Server Core installation)
- Windows 10 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 Version 1607 for x64-based Systems
- Windows Server 2016
- Windows Server 2016 (Server Core installation)
- Remote Desktop client for Windows Desktop
Apps
- Microsoft Remote Desktop for Mac
- Microsoft Remote Desktop for IoS
Security Updates (9)
Revision History
- 2021-01-12: Information published.
- 2021-12-14: The following revisions have been made: 1) In the Security Updates table, added Microsoft Remote Desktop for iOS and Microsoft Remote Desktop for Mac as these versions are affected by CVE-2021-1669. 2) New updates are available that comprehensively address this vulnerability for the following: Microsoft Remote Desktop, Microsoft Remote Desktop for Android, and Remote Desktop client for Windows Desktop. Customers running any of these versions of Remote Desktop should check for updates and ensure that they have the most recent update installed. Links to the updates on the respective app stores are listed in the Security Updates table.