Information Disclosure Vulnerability in Microsoft Remote Desktop Connection Manager
CVE-2020-0765

5.5MEDIUM

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
12 March 2020

Summary

An information disclosure vulnerability exists in Microsoft Remote Desktop Connection Manager due to improper XML parsing. This issue allows an attacker to exploit the application by sending specially crafted XML input that references external entities, which could lead to unauthorized access to sensitive information. Users and organizations utilizing the affected versions of RDCMan should ensure they implement recommended security practices and consider applying any available updates to mitigate this risk.

Affected Version(s)

Remote Desktop Connection Manager 2.7 = unspecified

References

EPSS Score

15% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.