CVE-2016-0036

HIGH

Microsoft Windows - Remote Code Execution via Remote Desktop Protocol

Title source: llm
STIX 2.1

Description

The Remote Desktop Protocol (RDP) implementation in Microsoft Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows remote authenticated users to execute arbitrary code via crafted data, aka "Remote Desktop Protocol (RDP) Elevation of Privilege Vulnerability."

References (2)

Core 2
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2016/ms16-017
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1034981

Scores

CVSS v3 8.1
EPSS 0.1143
EPSS Percentile 95.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (5)
microsoft/windows_10
microsoft/windows_7
microsoft/windows_8.1
microsoft/windows_server_2012
microsoft/windows_server_2012 r2
Published Feb 10, 2016
Tracked Since Feb 18, 2026