First published: Tue Jan 14 2020(Updated: )
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0610.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-0609 has a critical severity rating due to its potential for remote code execution.
To fix CVE-2020-0609, apply the latest security updates released by Microsoft for affected Windows Server versions.
CVE-2020-0609 affects Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, and Windows Server 2019.
Yes, CVE-2020-0609 can be exploited remotely by an unauthenticated attacker through remote desktop protocol (RDP) connections.
The potential impacts of CVE-2020-0609 include unauthorized access, data compromise, and full system control by attackers.