QID 91901

Date Published: 2022-05-11

QID 91901: Microsoft Windows Remote Desktop Protocol (RDP) Multiple Vulnerabilities for May 2022

Remote Desktop client for Windows Desktop to access Windows apps and desktops remotely from a different Windows device.

CVE-2022-26940: Remote Desktop Protocol Client Information Disclosure Vulnerability.
CVE-2022-22017: Remote Desktop Client Remote Code Execution Vulnerability.
Affected Versions:
Windows Remote Desktop Client Versions prior to version 1.2.3130

QID Detection Logic:(Authenticated)
This QID checks for a vulnerable Remote Desktop client

Upon connecting, the malicious server could execute code on the victim's system in the context of the targeted user.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customers are advised to refer to Microsoft Advisory CVE-2022-26940 And CVE-2022-22017for more details.

    CVEs related to QID 91901

    Software Advisories
    Advisory ID Software Component Link
    CVE-2022-22017 URL Logo msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-22017
    CVE-2022-26940 URL Logo msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-26940