QID 91875

Date Published: 2022-03-09

QID 91875: Microsoft Windows Remote Desktop Client Multiple Vulnerabilities for March 2022

Remote Desktop client for Windows Desktop to access Windows apps and desktops remotely from a different Windows device.

CVE-2022-24503: Remote Desktop Protocol Client Information Disclosure Vulnerability.
CVE-2022-21990:Remote Desktop Client Remote Code Execution Vulnerability.
Affected Versions:-
Remote Desktop client Prior to 1.2.2925.
QID Detection Logic:(Authenticated)
This QID checks for a vulnerable Remote Desktop client

An attacker with control of a Remote Desktop Server could trigger a remote code execution (RCE) on the RDP client machine when a victim connects to the attacking server with the vulnerable Remote Desktop Client.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to refer to Microsoft Advisory CVE-2022-24503 And CVE-2022-21990for more details.

    CVEs related to QID 91875

    Software Advisories
    Advisory ID Software Component Link
    CVE-2022-21990 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21990
    CVE-2022-24503 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2022-24503