CVE-2020-1374

Description

A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka Remote Desktop Client Remote Code Execution Vulnerability.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
EPSS Score
Exploitation Probability
13.201

Associated Vulnerability

VulnerabilityOS Platform
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1809 for x64-based Systems (KB4558998)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1809 for x86-based Systems (KB4558998)Windows
VBScript Remote Code Execution Vulnerability for Windows Server 2019 for x64-based Systems (KB4558998)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1709 for x86-based Systems (KB4565508)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1709 for x64-based Systems (KB4565508)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1803 for x64-based Systems (KB4565489)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1803 for x86-based Systems (KB4565489)Windows
VBScript Remote Code Execution Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4565524)(ESU)Windows
VBScript Remote Code Execution Vulnerability for Windows 7 for x86-based Systems (KB4565524)(ESU)Windows
VBScript Remote Code Execution Vulnerability for Windows 7 for x64-based Systems (KB4565524) (ESU)Windows
Jet Database Engine Remote Code Execution Vulnerability for Windows 7 for x86-based Systems (KB4565539) (ESU)Windows
Jet Database Engine Remote Code Execution Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB4565539) (ESU)Windows
Jet Database Engine Remote Code Execution Vulnerability for Windows 7 for x64-based Systems (KB4565539) (ESU)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB4565511)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB4565511)Windows
VBScript Remote Code Execution Vulnerability for Windows Server 2016 for x64-based Systems (KB4565511)Windows
VBScript Remote Code Execution Vulnerability for Windows 8.1 for x86-based Systems (KB4565541)Windows
VBScript Remote Code Execution Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4565541)Windows
VBScript Remote Code Execution Vulnerability for Windows 8.1 for x64-based Systems (KB4565541)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1507 for x86-based Systems (KB4565513)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1507 for x64-based Systems (KB4565513)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1903 for x64-based Systems (KB4565483)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1909 for x64-based Systems (KB4565483)Windows
VBScript Remote Code Execution Vulnerability for Windows Server, version 1903 for x64-based Systems (KB4565483)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1903 for x86-based Systems (KB4565483)Windows
VBScript Remote Code Execution Vulnerability for Windows Server, version 1909 for x64-based Systems (KB4565483)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 1909 for x86-based Systems (KB4565483)Windows
Jet Database Engine Remote Code Execution Vulnerability for Windows Server 2012 R2 for x64-based Systems (KB4565540)Windows
Jet Database Engine Remote Code Execution Vulnerability for Windows 8.1 for x86-based Systems (KB4565540)Windows
Jet Database Engine Remote Code Execution Vulnerability for Windows 8.1 for x64-based Systems (KB4565540)Windows
Jet Database Engine Remote Code Execution Vulnerability for Windows Server 2012 for x64-based Systems (KB4565535)Windows
VBScript Remote Code Execution Vulnerability for Windows Server 2012 for x64-based Systems (KB4565537)Windows
VBScript Remote Code Execution Vulnerability for Windows Server, version 2004 for x64-based Systems (KB4565503)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 2004 for x86-based Systems (KB4565503)Windows
VBScript Remote Code Execution Vulnerability for Windows 10 Version 2004 for x64-based Systems (KB4565503)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-292382020-07 Cumulative Update for Windows 10 Version 1809 for x64-based Systems (KB4558998) (KB4569509) (CVE-2020-1350)
PATCH-292392020-07 Cumulative Update for Windows 10 Version 1809 for x86-based Systems (KB4558998,KB4569509) (CVE-2020-1350)
PATCH-292402020-07 Cumulative Update for Windows Server 2019 for x64-based Systems (KB4558998,KB4569509) (CVE-2020-1350)
PATCH-292462020-07 Cumulative Update for Windows 10 Version 1709 for x86-based Systems (KB4565508)
PATCH-292472020-07 Cumulative Update for Windows 10 Version 1709 for x64-based Systems (KB4565508)
PATCH-292412020-07 Cumulative Update for Windows 10 Version 1803 for x64-based Systems (KB4565489)
PATCH-292422020-07 Cumulative Update for Windows 10 Version 1803 for x86-based Systems (KB4565489)
PATCH-292712020-07 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems (KB4565524,KB4569509) (CVE-2020-1350) (ESU)
PATCH-292722020-07 Security Monthly Quality Rollup for Windows 7 for x86-based Systems (KB4565524,KB4569509) (CVE-2020-1350) (ESU)
PATCH-292732020-07 Security Monthly Quality Rollup for Windows 7 for x64-based Systems (KB4565524,KB4569509) (CVE-2020-1350) (ESU)
PATCH-292752020-07 Security Only Quality Update for Windows 7 for x86-based Systems (KB4565539,KB4569509) (CVE-2020-1350) (ESU)
PATCH-292762020-07 Security Only Quality Update for Windows Server 2008 R2 for x64-based Systems (KB4565539,KB4569509) (CVE-2020-1350) (ESU)
PATCH-292772020-07 Security Only Quality Update for Windows 7 for x64-based Systems (KB4565539,KB4569509) (CVE-2020-1350) (ESU)
PATCH-292542020-07 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4565511) (CVE-2020-1350)
PATCH-292552020-07 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4565511) (CVE-2020-1350)
PATCH-292562020-07 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4565511) (CVE-2020-1350)
PATCH-292682020-07 Security Monthly Quality Rollup for Windows 8.1 for x86-based Systems (KB4565541,KB4569509) (CVE-2020-1350)
PATCH-292692020-07 Security Monthly Quality Rollup for Windows Server 2012 R2 for x64-based Systems (KB4565541,KB4569509) (CVE-2020-1350)
PATCH-292702020-07 Security Monthly Quality Rollup for Windows 8.1 for x64-based Systems (KB4565541,KB4569509) (CVE-2020-1350)
PATCH-292572020-07 Cumulative Update for Windows 10 Version 1507 for x86-based Systems (KB4565513)
PATCH-292582020-07 Cumulative Update for Windows 10 Version 1507 for x64-based Systems (KB4565513)
PATCH-292482020-07 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4565483,KB4569509) (CVE-2020-1350)
PATCH-292492020-07 Cumulative Update for Windows 10 Version 1909 for x64-based Systems (KB4565483,KB4569509) (CVE-2020-1350)
PATCH-292502020-07 Cumulative Update for Windows Server, version 1903 for x64-based Systems (KB4565483,KB4569509) (CVE-2020-1350)
PATCH-292512020-07 Cumulative Update for Windows 10 Version 1903 for x86-based Systems (KB4565483,KB4569509) (CVE-2020-1350)
PATCH-292522020-07 Cumulative Update for Windows Server, version 1909 for x64-based Systems (KB4565483,KB4569509) (CVE-2020-1350)
PATCH-292532020-07 Cumulative Update for Windows 10 Version 1909 for x86-based Systems (KB4565483,KB4569509) (CVE-2020-1350)
PATCH-292342020-07 Security Only Quality Update for Windows Server 2012 R2 for x64-based Systems (KB4565540,KB4569509) (CVE-2020-1350)
PATCH-292352020-07 Security Only Quality Update for Windows 8.1 for x86-based Systems (KB4565540,KB4569509) (CVE-2020-1350)
PATCH-292362020-07 Security Only Quality Update for Windows 8.1 for x64-based Systems (KB4565540,KB4569509) (CVE-2020-1350)
PATCH-292372020-07 Security Only Quality Update for Windows Server 2012 for x64-based Systems (KB4565535,KB4569509) (CVE-2020-1350)
PATCH-292742020-07 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB4565537,KB4569509) (CVE-2020-1350)
PATCH-292432020-07 Cumulative Update for Windows Server, version 2004 for x64-based Systems (KB4565503,KB4569509) (CVE-2020-1350)
PATCH-292442020-07 Cumulative Update for Windows 10 Version 2004 for x86-based Systems (KB4565503,KB4569509) (CVE-2020-1350)
PATCH-292452020-07 Cumulative Update for Windows 10 Version 2004 for x64-based Systems (KB4565503,KB4569509) (CVE-2020-1350)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234