Permissions, Privileges, and Access Controls in Microsoft Windows and Windows Server - CVE-2020-0655
Published: February 11, 2020 / Updated: May 26, 2020
Vulnerability details
The vulnerability allows a remote authenticated user to escalate privileges on the system.
The vulnerability exists due to the way Remote Desktop Services formerly known as Terminal Services handles clipboard redirection. A remote authenticated user with access to a system running Remote Desktop Services can abuse clipboard redirection and execute arbitrary code in the context of another user's session.
Affected software
Windows Server
Solutions Enabler Virtual Appliance
Solutions Enabler
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax
How to mitigate CVE-2020-0655
Solutions Enabler - addressed in versions 9.0.0.19, 9.1.0.6
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.0.2.18, 9.1.0.17
Unisphere for PowerMax - addressed in versions 9.0.2.18, 9.1.0.17