CVE-2011-0029

high Microsoft
CVSS v3 Base Score
7.4
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
34.7%
Exploitation probability in 30 days
Top 3% most likely to be exploited
Attack Characteristics
Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
None
Confidentiality
High
Integrity
High
Availability
High
Published: March 9, 2011 (5545 days ago)
Last Modified: April 29, 2026
Vendor: Microsoft
Source: NVD

Description

Untrusted search path vulnerability in the client in Microsoft Remote Desktop Connection 5.2, 6.0, 6.1, and 7.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .rdp file, aka "Remote Desktop Insecure Library Loading Vulnerability."

CWE

NVD-CWE-Other

Affected Products

microsoft remote desktop connection clientmicrosoft windows 2003 servermicrosoft windows server 2003microsoft windows xpmicrosoft windows 7microsoft windows server 2008microsoft windows vista

References