CVE-2009-1929: Buffer Overflow
Heap-based buffer overflow in the Microsoft Terminal Services Client ActiveX control running RDP 6.1 on Windows XP SP2, Vista SP1 or SP2, or Server 2008 Gold or SP2; or 5.2 or 6.1 on Windows XP SP3; allows remote attackers to execute arbitrary code via unspecified parameters to unknown methods, aka "Remote Desktop Connection ActiveX Control Heap Overflow Vulnerability."
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
Which systems are identified as affected?
The affected configurations listed are Windows XP SP2 with RDP 6.1, Windows XP SP3 with RDP 5.2 or 6.1, Windows Vista SP1 or SP2 with RDP 6.1, and Windows Server 2008 Gold or SP2 with RDP 6.1. Windows Server 2003 is listed in the software inventory, but the affected RDP version and service-pack combination is not specified in the provided data.
What does an attacker need to exploit this issue?
The vulnerability is remotely exploitable without authentication. Exploitation involves sending unspecified parameters to unknown methods in the Remote Desktop Connection ActiveX control.
What is the potential impact of successful exploitation?
A remote attacker can execute arbitrary code. The provided severity vector indicates complete impact to confidentiality, integrity, and availability.
Is a fix available?
Yes. A patch is available.