CVE-2020-0610

CRITICAL EXPLOITED RANSOMWARE

Microsoft Windows Server 2012 - Remote Code Execution

Title source: rule

Description

A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0609.

Exploits (6)

nomisec WRITEUP 2 stars
by ImBIOS · poc
https://github.com/ImBIOS/lab-cve-2020-0610
nomisec WRITEUP
by Riocipta75 · poc
https://github.com/Riocipta75/lab-cve-2020-0610
gitlab WORKING POC
by mrlayle · poc
https://gitlab.com/mrlayle/BlueGate
patchapalooza WORKING POC
by ind3p3nd3nt · dos
https://gitlab.com/ind3p3nd3nt/BlueGate
exploitdb WORKING POC
by ollypwn · c++doswindows
https://www.exploit-db.com/exploits/47963
exploitdb WORKING POC
by ollypwn · c++doswindows
https://www.exploit-db.com/exploits/47964

Scores

CVSS v3 9.8
EPSS 0.8617
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation Intel

VulnCheck KEV 2020-01-14
Ransomware Use Confirmed

Classification

Status published

Affected Products (4)

microsoft/windows_server_2012
microsoft/windows_server_2012
microsoft/windows_server_2016
microsoft/windows_server_2019

Timeline

Published Jan 14, 2020
Tracked Since Feb 18, 2026