CVE-2020-0609

CRITICAL EXPLOITED IN THE WILD RANSOMWARE

Microsoft Windows Server 2012 - Remote Code Execution

Title source: rule

Description

A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0610.

Exploits (9)

nomisec WORKING POC 250 stars
by ly4k · poc
https://github.com/ly4k/BlueGate
nomisec WORKING POC 78 stars
by ioncodes · poc
https://github.com/ioncodes/BlueGate
nomisec SCANNER 69 stars
by MalwareTech · poc
https://github.com/MalwareTech/RDGScanner
nomisec SCANNER 41 stars
by ruppde · poc
https://github.com/ruppde/rdg_scanner_cve-2020-0609
nomisec WORKING POC 2 stars
by Archi73ct · poc
https://github.com/Archi73ct/CVE-2020-0609
gitlab WORKING POC
by ind3p3nd3nt · poc
https://gitlab.com/ind3p3nd3nt/BlueGate
gitlab WORKING POC
by mrlayle · poc
https://gitlab.com/mrlayle/BlueGate
exploitdb WORKING POC
cppdoswindows
https://www.exploit-db.com/exploits/47964
exploitdb WORKING POC
cppdoswindows
https://www.exploit-db.com/exploits/47963

Scores

CVSS v3 9.8
EPSS 0.8978
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2020-01-14
InTheWild.io 2021-08-09
Ransomware Use Confirmed
Status published
Products (4)
microsoft/windows_server_2012
microsoft/windows_server_2012 r2
microsoft/windows_server_2016
microsoft/windows_server_2019
Published Jan 14, 2020
Tracked Since Feb 18, 2026