vendor:
Remote Desktop Protocol (RDP)
by:
Unknown
9.8
CVSS
CRITICAL
Remote Code Execution
119
CWE
Product Name: Remote Desktop Protocol (RDP)
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2021-xxxx
CPE: a:microsoft:rdp
Platforms Tested: Windows 7
2021
RDP pool_spray Remote Code Execution
This exploit allows remote code execution on a target machine by leveraging a vulnerability in the RDP protocol. By sending a specially crafted payload, an attacker can overwrite memory and execute arbitrary code on the target system. This exploit has been tested and found to be successful on Windows 7 systems.
Mitigation:
To mitigate this vulnerability, it is recommended to apply the latest security patches and updates provided by the vendor. Additionally, restricting access to the RDP service to trusted networks or implementing network-level controls can help reduce the risk of exploitation.