CVE-2020-0610

CRITICAL EXPLOITED RANSOMWARE

Microsoft Windows Server 2012 - Remote Code Execution

Title source: rule

Description

A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0609.

Exploits (6)

exploitdb WORKING POC
by ollypwn · c++doswindows
https://www.exploit-db.com/exploits/47964
exploitdb WORKING POC
by ollypwn · c++doswindows
https://www.exploit-db.com/exploits/47963
nomisec WRITEUP 2 stars
by ImBIOS · poc
https://github.com/ImBIOS/lab-cve-2020-0610
gitlab WORKING POC
by mrlayle · poc
https://gitlab.com/mrlayle/BlueGate
nomisec WRITEUP
by Riocipta75 · poc
https://github.com/Riocipta75/lab-cve-2020-0610
patchapalooza WORKING POC
by ind3p3nd3nt · dos
https://gitlab.com/ind3p3nd3nt/BlueGate

Scores

CVSS v3 9.8
EPSS 0.8446
EPSS Percentile 99.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2020-01-14
Ransomware Use Confirmed
Status published
Products (4)
microsoft/windows_server_2012
microsoft/windows_server_2012 r2
microsoft/windows_server_2016
microsoft/windows_server_2019
Published Jan 14, 2020
Tracked Since Feb 18, 2026