Vulnerability Details CVE-2011-0029
Untrusted search path vulnerability in the client in Microsoft Remote Desktop Connection 5.2, 6.0, 6.1, and 7.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .rdp file, aka "Remote Desktop Insecure Library Loading Vulnerability."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.34
EPSS Ranking 96.7%
CVSS Severity
CVSS v3 Score 7.4
CVSS v2 Score 9.3
Products affected by CVE-2011-0029
-
cpe:2.3:a:microsoft:remote_desktop_connection_client:5.2
-
cpe:2.3:a:microsoft:remote_desktop_connection_client:6.0
-
cpe:2.3:a:microsoft:remote_desktop_connection_client:6.1
-
cpe:2.3:a:microsoft:remote_desktop_connection_client:7.0
-
cpe:2.3:o:microsoft:windows_2003_server:-
-
cpe:2.3:o:microsoft:windows_7:-
-
cpe:2.3:o:microsoft:windows_server_2003:-
-
cpe:2.3:o:microsoft:windows_server_2003:r2
-
cpe:2.3:o:microsoft:windows_server_2008:-
-
cpe:2.3:o:microsoft:windows_server_2008:r2
-
cpe:2.3:o:microsoft:windows_vista:-
-
cpe:2.3:o:microsoft:windows_xp:-
-
cpe:2.3:o:microsoft:windows_xp:unknown