CVE-2009-1929: Buffer Overflow

Published Aug 12, 2009
·
Updated

Heap-based buffer overflow in the Microsoft Terminal Services Client ActiveX control running RDP 6.1 on Windows XP SP2, Vista SP1 or SP2, or Server 2008 Gold or SP2; or 5.2 or 6.1 on Windows XP SP3; allows remote attackers to execute arbitrary code via unspecified parameters to unknown methods, aka "Remote Desktop Connection ActiveX Control Heap Overflow Vulnerability."

Affected Software

17 affected components
Microsoft Windows 2003 Server=sp2
Microsoft Windows 2003 Server=sp2
Microsoft Windows 2003 Server=sp2
Microsoft Windows Server 2008
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008
Microsoft Windows Server 2008
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Vista=sp1
Microsoft Windows Vista=sp2
Microsoft Windows Vista
Microsoft Windows XP=sp2
Microsoft Windows XP=sp2
Microsoft Windows XP=sp3
Microsoft Windows Vista=sp2
Microsoft Windows Vista=sp1

Event History

Aug 12, 2009
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description

Frequently Asked Questions

1

Which systems are identified as affected?

The affected configurations listed are Windows XP SP2 with RDP 6.1, Windows XP SP3 with RDP 5.2 or 6.1, Windows Vista SP1 or SP2 with RDP 6.1, and Windows Server 2008 Gold or SP2 with RDP 6.1. Windows Server 2003 is listed in the software inventory, but the affected RDP version and service-pack combination is not specified in the provided data.

2

What does an attacker need to exploit this issue?

The vulnerability is remotely exploitable without authentication. Exploitation involves sending unspecified parameters to unknown methods in the Remote Desktop Connection ActiveX control.

3

What is the potential impact of successful exploitation?

A remote attacker can execute arbitrary code. The provided severity vector indicates complete impact to confidentiality, integrity, and availability.

4

Is a fix available?

Yes. A patch is available.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203