HomeSecurityMicrosoft Windows: CVE-2019-9510 flaw gives hackers access

Microsoft Windows: CVE-2019-9510 flaw gives hackers access

A new flaw has been found in RDP (Microsoft Remote Windows Protocol). It was discovered by security expert Joe Tammariello of Carnegie Mellon University's Software Engineering Institute (SEI).

Microsoft Windows

This flaw (CVE-2019-9510) if discovered by a hacker, could allow them to access the customer's system by bypassing the lock screen even if it is locked.

This issue primarily affects Windows 10 1803 and Server 2019 versions. In order for someone to exploit this flaw, physical access to the system is required. Microsoft Windows Remote Desktop requires clients to authenticate using Network Level Authentication (NLA). This is what potentially allows someone to bypass the lock screen.

The handling of Microsoft Remote Windows Protocol, which is based on NLA, has changed. This can cause unexpected behavior with respect to locking. If a network causes a temporary RDP disconnection, upon automatic reconnect, the RDP session will be restored to an unlocked state, regardless of what the system actually is.

A hypothetical scenario according to CERT is as follows. A user connects to Windows 10 1803 or Server 2019 (or another system using RDP). Then, they lock the remote device. A hacker can then interrupt the client system's network connectivity, which would unlock the connection to the remote system.

The CERT also recommends that the local system should remain shut down, unlike the remote system. RDP sessions should also be disconnected, rather than locked, to terminate the current session and prevent automatic RDP session reconnection.

Tammariello has been reporting the issue to Microsoft since April 19. However, the company has unfortunately not accepted these claims as a problem, stating that they do not meet the Windows Security Maintenance Criteria.

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS