CVE-2013-1296

Description

The Remote Desktop ActiveX control in mstscax.dll in Microsoft Remote Desktop Connection Client 6.1 and 7.0 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a web page that triggers access to a deleted object, and allows remote RDP servers to execute arbitrary code via unspecified vectors that trigger access to a deleted object, aka RDP ActiveX Control Remote Code Execution Vulnerability.

Risk Information

Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
53.982

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Windows XP (KB2813345)Windows
Security Update for Windows Server 2003 (KB2813345)Windows
Security Update for Windows Vista (KB2813345)Windows
Security Update for Windows Server 2008 (KB2813345)Windows
Security Update for Windows XP x64 Edition (KB2813345)Windows
Security Update for Windows Server 2003 x64 Edition (KB2813345)Windows
Security Update for Windows Vista for x64-based Systems (KB2813345)Windows
Security Update for Windows Server 2008 x64 Edition (KB2813345)Windows
Security Update for Windows XP (KB2813347)Windows
Security Update for Windows Vista (KB2813347)Windows
Security Update for Windows 7 (KB2813347) x86 based systemsWindows
Security Update for Windows 7 (KB2813347) x86 based systems for SP1Windows
Security Update for Windows Vista for x64-based Systems (KB2813347)Windows
Security Update for Windows 7 for x64-based Systems (KB2813347)Windows
Security Update for Windows 7 for x64-based Systems (KB2813347) for SP1Windows
Security Update for Windows Server 2008 R2 x64 Edition (KB2813347)Windows
Security Update for Windows Server 2008 R2 x64 Edition (KB2813347) for SP1Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-13402Security Update for Windows Server 2003 (KB2813345)
PATCH-13403Security Update for Windows Vista (KB2813345)
PATCH-13404Security Update for Windows Server 2008 (KB2813345)
PATCH-13405Security Update for Windows XP x64 Edition (KB2813345)
PATCH-13406Security Update for Windows Server 2003 x64 Edition (KB2813345)
PATCH-13407Security Update for Windows Vista for x64-based Systems (KB2813345)
PATCH-13408Security Update for Windows Server 2008 x64 Edition (KB2813345)
PATCH-13410Security Update for Windows Vista (KB2813347)
PATCH-13411Security Update for Windows 7 (KB2813347)
PATCH-13412Security Update for Windows 7 (KB2813347)
PATCH-13413Security Update for Windows Vista for x64-based Systems (KB2813347)
PATCH-13414Security Update for Windows 7 for x64-based Systems (KB2813347)
PATCH-13415Security Update for Windows 7 for x64-based Systems (KB2813347)
PATCH-13416Security Update for Windows Server 2008 R2 x64 Edition (KB2813347)
PATCH-13417Security Update for Windows Server 2008 R2 x64 Edition (KB2813347)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234