CVE-2016-0019

HIGH

Windows 10 - Remote Desktop Protocol Security Bypass via Blank-Password Account

Title source: llm
STIX 2.1

Description

The Remote Desktop Protocol (RDP) service implementation in Microsoft Windows 10 Gold and 1511 allows remote attackers to bypass intended access restrictions and establish sessions for blank-password accounts via a modified RDP client, aka "Windows Remote Desktop Protocol Security Bypass Vulnerability."

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1034659

Scores

CVSS v3 8.1
EPSS 0.1224
EPSS Percentile 95.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-254
Status published
Products (2)
microsoft/windows_10 (2 CPE variants)
microsoft/windows_10 1511 (2 CPE variants)
Published Jan 13, 2016
Tracked Since Feb 18, 2026