CVE-2021-34535: Remote Desktop Client Remote Code Execution Vulnerability

Overview

Severity
High (CVSS 8.8)
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Category
Remote Code Execution
Exploit Status
Not Exploited
Exploitation Likelihood
More Likely
Patch Tuesday
2021-Aug
Released
2021-08-10
Last Updated
2021-08-10
EPSS Score
4.76% (percentile: 89.5%)

FAQ

How could an attacker exploit this vulnerability? In the case of a Remote Desktop connection, an attacker with control of a Remote Desktop Server could trigger a remote code execution (RCE) on the machine when a victim connects to the attacking server with the vulnerable Remote Desktop Client. In the case of Hyper-V, a malicious program running in a guest VM could trigger guest-to-host RCE by exploiting this vulnerability in the Hyper-V Viewer when a victim running on the host connects to the attacking Hyper-V guest.

Affected Products (30)

Other

  • 11568
  • 11569
  • 11570
  • 11571
  • 11712
  • 11713
  • 11714
  • 11849
  • 11896
  • 11897
  • 11898
  • 11766
  • 11767
  • 11768
  • 11800
  • 11801
  • 11802
  • 10729
  • 10735
  • 10852
  • 10853
  • 10816
  • 10047
  • 10048
  • 10481
  • 10482
  • 10484
  • 10051
  • 10378
  • 10483

Security Updates (12)

Acknowledgments

Malcolm Stagg

Revision History

  • 2021-08-10: Information published.
  • 2021-08-10: Updated links to security updates. This is an informational change only.