Improper input validation in Microsoft Windows and Windows Server - CVE-2018-0976

 

Improper input validation in Microsoft Windows and Windows Server - CVE-2018-0976

Published: April 10, 2018 / Updated: April 10, 2018


Vulnerability identifier: #VU11720
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-0976
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to an error when processing RDP connections. A remote attacker can send specially crafted RDP packets to the affected system and cause the RDP service on the target system to stop responding.



Affected software

Microsoft Windows
Windows Server

How to mitigate CVE-2018-0976

Install updates from vendor's website.


External References

Related Security Bulletins