QID 91875
Date Published: 2022-03-09
QID 91875: Microsoft Windows Remote Desktop Client Multiple Vulnerabilities for March 2022
Remote Desktop client for Windows Desktop to access Windows apps and desktops remotely from a different Windows device.
CVE-2022-24503: Remote Desktop Protocol Client Information Disclosure Vulnerability.
CVE-2022-21990:Remote Desktop Client Remote Code Execution Vulnerability.
Affected Versions:-
Remote Desktop client Prior to 1.2.2925.
QID Detection Logic:(Authenticated)
This QID checks for a vulnerable Remote Desktop client
An attacker with control of a Remote Desktop Server could trigger a remote code execution (RCE) on the RDP client machine when a victim connects to the attacking server with the vulnerable Remote Desktop Client.
Solution
Customers are advised to refer to Microsoft Advisory CVE-2022-24503 And CVE-2022-21990for more details.
Vendor References
- CVE-2022-21990 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21990 - CVE-2022-24503 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24503
CVEs related to QID 91875
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-21990 |
|
||
| CVE-2022-24503 |
|