CVE-2020-16896: Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
<p>An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p>To exploit this vulnerability, an attacker would need to run a specially crafted application against a server which provides Remote Desktop Protocol (RDP) services.</p> <p>The update addresses the vulnerability by correcting how RDP handles connection requests.</p>
Other sources
An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability'.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-16896?
CVE-2020-16896 is rated as important by Microsoft due to the potential for information disclosure.
How do I fix CVE-2020-16896?
To mitigate CVE-2020-16896, it is recommended to apply the latest security updates provided by Microsoft.
What systems are affected by CVE-2020-16896?
CVE-2020-16896 affects various versions of Microsoft Windows, including Windows 7, 8.1, 10, and several Windows Server iterations.
What type of vulnerability is CVE-2020-16896?
CVE-2020-16896 is classified as an information disclosure vulnerability affecting the Remote Desktop Protocol.
Can CVE-2020-16896 be exploited remotely?
Yes, CVE-2020-16896 can be exploited remotely if an attacker connects to the vulnerable system using RDP and sends specially crafted requests.