CVE-2020-16927: Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability
<p>A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could cause the RDP service on the target system to stop responding.</p> <p>To exploit this vulnerability, an attacker would need to run a specially crafted application against a server which provides Remote Desktop Protocol (RDP) services.</p> <p>The update addresses the vulnerability by correcting how RDP handles connection requests.</p>
Other sources
A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-16927?
CVE-2020-16927 is classified as a denial of service vulnerability.
How do I fix CVE-2020-16927?
To fix CVE-2020-16927, apply the latest security updates provided by Microsoft for affected Windows versions.
Which versions of Windows are affected by CVE-2020-16927?
Affected versions of Windows include Windows 10, Windows 8.1, and various versions of Windows Server.
What could an attacker achieve by exploiting CVE-2020-16927?
An attacker exploiting CVE-2020-16927 could cause the Remote Desktop Protocol service to crash, resulting in a denial of service.
Are there any workarounds for CVE-2020-16927?
While the primary mitigation is to apply updates, disabling Remote Desktop may serve as a temporary workaround.