CVE-2020-0609 is a critical remote code execution vulnerability affecting Windows Remote Desktop Gateway (RD Gateway) in Windows Server 2012, 2016, and 2019. An unauthenticated attacker can exploit this vulnerability by sending specially crafted RDP requests to the target system. With a CVSS score of 9.8, this vulnerability allows for complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, proof-of-concept denial-of-service exploits exist, and the vulnerability has garnered significant community discussion and media attention, including demonstrations of RCE exploits. Despite the lack of public RCE exploit code, the high risk and ease of exploitation necessitate immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2019:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.