CVE-2020-0609 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 77.7% (pctl 100)
Patch early
A public exploit exists.
Description
A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0610.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 77.68% — more likely to be exploited than 100% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2020-01-14 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| microsoft | windows server 2012 |
| microsoft | windows server 2016 |
| microsoft | windows server 2019 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC) | 2020-01-23 |
| exploit-db | Remote Desktop Gateway - 'BlueGate' Denial of Service (PoC) | 2020-01-23 |
References
→ the Explorer · watch your stack · NVD