Get a Pentest and security assessment of your IT network.

Cyber Security

Improper Microsoft Patch for Reverse RDP Attacks Leaves 3rd-Party RDP Clients Vulnerable

An Improperly Patched Path Traversal Flaw can be bypassed by replacing backward slashes in paths with forward slashes. Microsoft patched the vulnerability (CVE-2019-0887) as part of its July 2019 Patch Tuesday update. Microsoft acknowledged the improper fix and re-patched the flaw in February 2020 Patch Tuesday. Check Point researcher disclosed that Microsoft addressed the issue by adding a separate workaround in Windows while leaving the root of the bypass issue, an API function “PathCchCanonicalize,” unchanged.

Source: https://thehackernews.com/2020/05/reverse-rdp-attack-patch.html

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security