| Vulnerability Name: | CVE-2013-1296 (CCN-83092) | ||||||||
| Assigned: | 2013-04-09 | ||||||||
| Published: | 2013-04-09 | ||||||||
| Updated: | 2018-10-12 | ||||||||
| Summary: | The Remote Desktop ActiveX control in mstscax.dll in Microsoft Remote Desktop Connection Client 6.1 and 7.0 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code via a web page that triggers access to a deleted object, and allows remote RDP servers to execute arbitrary code via unspecified vectors that trigger access to a deleted object, aka "RDP ActiveX Control Remote Code Execution Vulnerability." | ||||||||
| CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
| CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-94 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2013-1296 Source: CCN Type: SA52911 Microsoft Windows Remote Desktop ActiveX Control Vulnerability Source: CCN Type: Microsoft Security Bulletin MS13-029 Vulnerability in Remote Desktop Client Could Allow Remote Code Execution (2828223) Source: CCN Type: Microsoft Security Bulletin MS15-082 Vulnerabilities in RDP Could Allow Remote Code Execution (3080348) Source: CCN Type: BID-58874 Microsoft Remote Desktop ActiveX Control CVE-2013-1296 Remote Code Execution Vulnerability Source: CERT Type: US Government Resource TA13-100A Source: MS Type: UNKNOWN MS13-029 Source: XF Type: UNKNOWN ms-cve20131296-code-exec(83092) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:16598 Source: CCN Type: ZDI-13-065 Microsoft Internet Explorer RDP ActiveX Control Remote Code Execution Vulnerability | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| Oval Definitions | |||||||||
| |||||||||
| BACK | |||||||||