QID 92013

QID 92013: Microsoft Windows Remote Desktop Protocol (RDP) Multiple Vulnerabilities for May 2023

Remote Desktop client for Windows Desktop to access Windows apps and desktops remotely from a different Windows device.

CVE-2023-24905: Remote Desktop Client Remote Code Execution Vulnerability
CVE-2023-28290: Microsoft Remote Desktop app for Windows Information Disclosure Vulnerability
Affected Versions:
Windows Remote Desktop Client Versions prior to 1.2.4240 version

QID Detection Logic:(Authenticated)
This QID checks for a vulnerable Remote Desktop client

An attacker could swap out a forged certificate with the same serial number resulting in a Man-In-The-Middle (MiTM) attack.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to Microsoft Advisory CVE-2023-24905 And CVE-2023-28290for more details.

    CVEs related to QID 92013

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-24905 URL Logo msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-24905
    CVE-2023-28290 URL Logo msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-28290