Microsoft Ignored RDP Vulnerability Until it Affected Hyper-V
#1
Quote:A vulnerability in Microsoft's Remote Desktop Protocol (RDP) can also be used to escape virtual machines running on Hyper-V, the virtualization technology in Azure and Windows 10.
 
The bug is a path traversal that leads to remote execution and was reported to Microsoft almost a year ago as affecting only RDP and remained unpatched until recently, when it was discovered that it impacts Microsoft's Hyper-V product.
 
Initially, Microsoft validated the finding but dismissed a fix motivating that it did "not meet our bar for servicing."
 
Eyal Itkin from Check Point published in February the technical details about the flaw as part of a larger research that covered multiple RDP vulnerabilities. His focus was on achieving a reverse RDP attack, where the server of a remote connection gains control over the client.
 
This was possible because two machines connected through RDP share the clipboard, which means that whatever is copied on the remote server can be pasted on the local client.

Read more here: https://www.bleepingcomputer.com/news/se...d-hyper-v/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
Microsoft Ignored RDP Vulnerability Until it Affected Hyper-V - by silversurfer - 08 August 19, 17:42

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.4.5  Fixed a p...Kool — 07:41
AxCrypt 3.0.0.85
AxCrypt 3.0.0.85: ...harlan4096 — 06:52
Sumatra PDF 3.6.1
Changes in 3.6.1: ...harlan4096 — 06:50
Microsoft Edge 146.0.3856.109
Version 146.0.3856...harlan4096 — 06:49
Ventoy 1.1.11
Ventoy 1.1.11 2...harlan4096 — 06:48

[-]
Birthdays
Today's Birthdays
avatar (47)creatralGuelm
avatar (38)procnipsut
avatar (44)accenwibly
avatar (41)ahyvily
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (46)MeighGoask
avatar (38)urumahiz
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)burntLaw
avatar (41)MrDoorsskibheeds
avatar (51)Toligo
avatar (46)Rodneykak
avatar (49)tradeSmode
avatar (39)vemedProkbior
avatar (38)RobertUtelt
avatar (36)Kiran78

[-]
Online Staff
There are no staff members currently online.

>