APP: Microsoft Windows Remote Desktop Protocol CVE-2020-16896 Information Disclosure

This signature detects attempts to exploit a known vulnerability against Windows Remote Desktop. A successful attack can lead to sensitive information disclosure.

Extended Description

An information disclosure vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests. An attacker who successfully exploited this vulnerability could obtain information to further compromise the users system. To exploit this vulnerability, an attacker would need to run a specially crafted application against a server which provides Remote Desktop Protocol (RDP) services. The update addresses the vulnerability by correcting how RDP handles connection requests.

Affected Products

Microsoft windows_server_2016

References

CVE: CVE-2020-16896

Short Name
APP:REMOTE:CVE-2020-16896-INFLK
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
APP
Keywords
CVE-2020-16896 Desktop Disclosure Information Microsoft Protocol Remote Windows
Release Date
10/12/2020
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

srx-branch-12.3

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx-12.3

vmx-19.3

srx-12.3

Sigpack Version
3665
False Positive
Unknown
Vendors

Microsoft

CVSS Score

5.0

Found a potential security threat?