CVE-2012-0002
The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, aka "Remote Desktop Protocol Vulnerability."
- Affected products
- Windows, Windows 7, Windows Embedded Standard 2009, Windows Server 2003, Windows Server 2008, Windows Vista, Windows Xp
- Microsoft Windows 7
- All versions
- Microsoft Windows Server 2003
- All versions
- Microsoft Windows Server 2008
- All versions
- Microsoft Windows Vista
- All versions
- Microsoft Windows Xp
- All versions
- Fix
- Available
- CVSS 2.0
- 9.3 HIGH
- EPSS
- 74.1% (99th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2012-03-13
CVE-2012-0002 at NVD
12 known exploits for CVE-2012-0002
Proof-of-concept code and exploit modules indexed by Sploitus
Alfred-TryHackMe-Walkthrough-Jenkins-Exploitation-Windows-Token-Privilege-Escalation
MS12-020 Microsoft Remote Desktop Checker
MS12-020 Microsoft Remote Desktop Use-After-Free Denial of Service
Exploit for Code Injection in Microsoft
Exploit for Code Injection in Microsoft
Exploit for Code Injection in Microsoft
Microsoft Terminal Services Use After Free (MS12-020)
MS12-020 Microsoft Remote Desktop Checker
Microsoft Terminal Services - Use-After-Free (MS12-020)
MS12-020 Microsoft Remote Desktop Use-After-Free DoS
Microsoft Windows远程桌面协议RDP远程代码执行漏洞(MS12-020)
MS12-020 Microsoft RDP Vulnerability Exploit PoC