Microsoft Ignored RDP Vulnerability Until it Affected Hyper-V
#1
Quote:A vulnerability in Microsoft's Remote Desktop Protocol (RDP) can also be used to escape virtual machines running on Hyper-V, the virtualization technology in Azure and Windows 10.
 
The bug is a path traversal that leads to remote execution and was reported to Microsoft almost a year ago as affecting only RDP and remained unpatched until recently, when it was discovered that it impacts Microsoft's Hyper-V product.
 
Initially, Microsoft validated the finding but dismissed a fix motivating that it did "not meet our bar for servicing."
 
Eyal Itkin from Check Point published in February the technical details about the flaw as part of a larger research that covered multiple RDP vulnerabilities. His focus was on achieving a reverse RDP attack, where the server of a remote connection gains control over the client.
 
This was possible because two machines connected through RDP share the clipboard, which means that whatever is copied on the remote server can be pasted on the local client.

Read more here: https://www.bleepingcomputer.com/news/se...d-hyper-v/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Free Download Manager 6.33.1.6648
Changes in 6.33.1....harlan4096 — 08:33
Brave 1.87.190 (Chromium 145.0.7632.109)
Release v1.87.190 ...harlan4096 — 08:32
LibreOffice 25.8.5
Berlin, 19 Februar...harlan4096 — 08:30
Google Chrome 145.0.7632.109/110
Google Chrome 145....harlan4096 — 08:29
Internet Download Manager 6.32 Build 9
Internet Download ...Kool — 00:41

[-]
Birthdays
Today's Birthdays
avatar (38)Michaelaburi
avatar (46)dpascoal
Upcoming Birthdays
avatar (46)dimaWeami
avatar (44)Baihu

[-]
Online Staff
There are no staff members currently online.

>