vendor:
Remote Desktop 10
by:
Saeed Hasanzadeh (Net.Hun73r)
7.5
CVSS
HIGH
Denial of Service
N/A
CWE
Product Name: Remote Desktop 10
Affected Version From: 10.2.4(134)
Affected Version To: 10.2.4(134)
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Mac OS Mojave(10.14.2)
2019
Microsoft Remote Desktop 10.2.4(134) – Denial of Service (PoC)
Run the python script, it will create a new file 'PoC.txt'. Copy the text from the generated PoC.txt file to clipboard and paste the text in the add Desktop > add user account >UserName. App will now crash.
Mitigation:
Update to the latest version of Microsoft Remote Desktop 10.2.4(134)