First published: Tue Jan 14 2020(Updated: )
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0609.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Server | ||
Microsoft Windows Server | =r2 | |
Microsoft Windows Server 2016 | ||
Microsoft Windows Server 2019 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-0610 is rated as critical due to its ability to allow remote code execution.
To fix CVE-2020-0610, apply the security update provided by Microsoft for your affected Windows Server version.
CVE-2020-0610 affects Microsoft Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, and Windows Server 2019.
CVE-2020-0610 describes a remote code execution attack that can occur through the Windows Remote Desktop Gateway.
Yes, CVE-2020-0610 can be exploited by an unauthenticated attacker connecting to the target system.