Lucene search

K
cve[email protected]CVE-2009-1929
HistoryAug 12, 2009 - 5:30 p.m.

CVE-2009-1929

2009-08-1217:30:00
CWE-119
web.nvd.nist.gov
34
cve-2009-1929
remote desktop connection
rdp 6.1
windows xp
vista
server 2008
buffer overflow
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.1 High

AI Score

Confidence

Low

0.935 High

EPSS

Percentile

99.1%

Heap-based buffer overflow in the Microsoft Terminal Services Client ActiveX control running RDP 6.1 on Windows XP SP2, Vista SP1 or SP2, or Server 2008 Gold or SP2; or 5.2 or 6.1 on Windows XP SP3; allows remote attackers to execute arbitrary code via unspecified parameters to unknown methods, aka “Remote Desktop Connection ActiveX Control Heap Overflow Vulnerability.”

Affected configurations

NVD
Node
microsoftwindows_2003_serverMatchsp2
OR
microsoftwindows_2003_serverMatchsp2itanium
OR
microsoftwindows_2003_serverMatchsp2x64
OR
microsoftwindows_server_2008itanium
OR
microsoftwindows_server_2008sp2x64
OR
microsoftwindows_server_2008Match--x32
OR
microsoftwindows_server_2008Match--x64
OR
microsoftwindows_server_2008Match-sp2itanium
OR
microsoftwindows_server_2008Match-sp2x86
OR
microsoftwindows_vistasp1
OR
microsoftwindows_vistasp2
OR
microsoftwindows_vistaMatch--x64
OR
microsoftwindows_xpsp2x64
OR
microsoftwindows_xpMatch-sp2
OR
microsoftwindows_xpMatch-sp3

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

8.1 High

AI Score

Confidence

Low

0.935 High

EPSS

Percentile

99.1%