CERT-In Vulnerability Note
CIVN-2014-0255
Microsoft Windows Remote Desktop Protocol Auditing Bypass Vulnerability
Original Issue Date:November 12, 2014
Severity Rating: HIGH
Systems Affected
- Windows Vista (Service Pack 2 and x64 Edition Service Pack 2)
- Windows Server 2008 (32-bit, x64-based and Itanium-based Systems Service Pack 2)
- Windows 7 (32-bit Systems and x64-based Systems Service Pack 1)
- Windows Server 2008 R2 x64-based Systems and Itanium-based Systems Service Pack 1
- Windows 8 and Windows 8.1 (32-bit Systems and x64-based Systems)
- Windows Server 2012 and Windows Server 2012 R2
- Windows RT and Windows RT 8.1
- Server Core installation option - Server 2008 (32-bit and x64-based Systems Service Pack 2)
- Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2012 and Windows Server 2012 R2
Overview
A vulnerability has been reported in Microsoft Windows RDP, which could allow an unauthenticated, remote attacker to bypass security restrictions.
Description
This vulnerability is caused as the Remote Desktop Protocol (RDP) does not properly log failed logon attempts. An unauthenticated, remote attacker could exploit this vulnerability and bypass the audit login security feature on a targeted system. If successfully exploited, this vulnerability could allow the attacker to conduct brute-force attacks without being noticed by the victim systems auditing security feature.
Note: By default, RDP for administration is not enabled on any Windows operating system.
Solution
Apply appropriate patch as mentioned in Microsoft Security Bulletin
MS14-074
Vendor Information
Microsoft
https://technet.microsoft.com/en-us/library/security/ms14-074
References
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=36278
Symantec
http://www.symantec.com/security_response/vulnerability.jsp?bid=70981
CVE Name
CVE-2014-6318
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|