vendor:
rdpy
by:
Eyal Karni
7.0
CVSS
HIGH
CVE-2018-0886
287
CWE
Product Name: rdpy
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2018-0886
CPE: N/A
Other Scripts:
N/A
Platforms Tested: Linux
2018
credssp
This is a poc code for exploiting CVE-2018-0886. It relies on a fork of the rdpy project, allowing also credssp relay.
Mitigation:
Uninstall relevant components such as cryptography,pyopenssl and follow the instructions in the described order.