QID 92013
QID 92013: Microsoft Windows Remote Desktop Protocol (RDP) Multiple Vulnerabilities for May 2023
Remote Desktop client for Windows Desktop to access Windows apps and desktops remotely from a different Windows device.
CVE-2023-24905: Remote Desktop Client Remote Code Execution Vulnerability
CVE-2023-28290: Microsoft Remote Desktop app for Windows Information Disclosure Vulnerability
Affected Versions:
Windows Remote Desktop Client Versions prior to 1.2.4240 version
QID Detection Logic:(Authenticated)
This QID checks for a vulnerable Remote Desktop client
An attacker could swap out a forged certificate with the same serial number resulting in a Man-In-The-Middle (MiTM) attack.
Solution
Customers are advised to refer to Microsoft Advisory CVE-2023-24905 And CVE-2023-28290for more details.
Vendor References
- CVE-2023-24905 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-24905 - CVE-2023-28290 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-28290
CVEs related to QID 92013
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-24905 |
|
||
| CVE-2023-28290 |
|