Information Disclosure Vulnerability in Microsoft Remote Desktop Connection Manager
CVE-2020-0765
5.5MEDIUM
Key Information:
- Vendor
- Microsoft
- Vendor
- CVE Published:
- 12 March 2020
Summary
An information disclosure vulnerability exists in Microsoft Remote Desktop Connection Manager due to improper XML parsing. This issue allows an attacker to exploit the application by sending specially crafted XML input that references external entities, which could lead to unauthorized access to sensitive information. Users and organizations utilizing the affected versions of RDCMan should ensure they implement recommended security practices and consider applying any available updates to mitigate this risk.
Affected Version(s)
Remote Desktop Connection Manager 2.7 = unspecified
References
EPSS Score
15% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved