CVE-2020-16896

HIGH EXPLOITED RANSOMWARE

Windows RDP - Information Disclosure via Specially Crafted Connection Requests

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2020-16896 has been observed exploited in the wild (reported by VulnCheck KEV), including in ransomware campaigns.

Description

<p>An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p>To exploit this vulnerability, an attacker would need to run a specially crafted application against a server which provides Remote Desktop Protocol (RDP) services.</p> <p>The update addresses the vulnerability by correcting how RDP handles connection requests.</p>

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.1046
EPSS Percentile 95.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

VulnCheck KEV 2021-08-19
Ransomware Use Confirmed
Status published
Products (20)
microsoft/windows_10
microsoft/windows_10 1607
microsoft/windows_10 1709
microsoft/windows_10 1803
microsoft/windows_10 1809
microsoft/windows_10 1903
microsoft/windows_10 1909
microsoft/windows_10 2004
microsoft/windows_7 (2 CPE variants)
microsoft/windows_8.1 (2 CPE variants)
... and 10 more
Published Oct 16, 2020
Tracked Since Feb 18, 2026