VDB

CVE-2020-0611

CVE-2020-0611 PUBLISHED CVSS 7.5 HIGH

A remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server, aka 'Remote Desktop Client Remote Code Execution Vulnerability'.

EPSS 8.10% · 92.3th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
8.10%
92.3th percentile

Affected Products

VendorProductVersions
microsoftwindows_server_2008r2, r2
microsoftwindows_101809, 1903, 1909
microsoftwindows_server_2019
MicrosoftWindows Serverversion 1803 (Core Installation), *, *
MicrosoftWindows Server, version 1909 (Server Core installation)unspecified
MicrosoftWindows Server, version 1903 (Server Core installation)*
microsoftwindows_8.1
MicrosoftWindows 10 Version 1903 for 32-bit Systemsunspecified
MicrosoftWindows 10 Version 1903 for x64-based Systems*
MicrosoftWindows 10 Version 1909 for 32-bit Systemsunspecified
microsoftwindows_7
MicrosoftWindows 10 Version 1903 for ARM64-based Systemsunspecified
MicrosoftWindows 10 Version 1909 for x64-based Systemsunspecified
MicrosoftWindows 10 Version 1909 for ARM64-based Systems*
MicrosoftWindows7 for x64-based Systems Service Pack 1, 10 Version 1607 for x64-based Systems, 10 Version 1607 for 32-bit Systems
microsoftwindows_server_20161803, 1903, 1909
microsoftwindows_rt_8.1
microsoftwindows_server_2012r2

Timeline

  • May 23, 2014 PoC Published
  • Jan 14, 2020 CVE Published
  • Jan 21, 2020 PoC Published
  • Jun 26, 2020 PoC Published
  • Apr 14, 2021 EPSS Score
  • Jun 22, 2021 EPSS Score
  • Oct 25, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 27, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jul 2, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›