Skip to main content

CVE detail

CVE-2012-0002

The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remote attackers to execute arbitrary code by sending crafted RDP packets triggering access to an object that (1) was not properly initialized or (2) is deleted, aka "Remote Desktop Protocol Vulnerability."

CVSS 9.3 · CriticalBuzz score 29.0

Buzz score

Why this CVE is surfacing

Buzz score total 29.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 19.5 · diversity 9.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
19.5
6 evidence mentions in the snapshot
Diversity score
9.5
4 sources across 1 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
6 source links · newest first
  • Microsoft is reportedly investigating whether the recent attacks against Microsoft Exchange servers could be linked to information leaked by a partner security firm. According to a report published by The Wall Street Journal, Microsoft is investigating whether the threat actors behind the recent wave of attacks on Microsoft Exchange servers worldwide may have obtained sensitive […]

    newssecurityaffairs.comMar 16, 2021, 7:48 AM
  • MOSCOW (AP) — Six years ago, a Russian-speaking cybersecurity researcher received an unsolicited email from Kate S. Milton.

    newswww.securityweek.comAug 1, 2018, 3:16 PM
  • Cloud computing environments such as those provided by Amazon and Google can be your passport to powerful computing resources without having to worry about typical provisioning and hardware issues, but if the recent Microsoft RDP vulnerability (CVE-2012-0002) is any guide, security is still a real problem. This talk from Shmoocon 2013 presents techniques to generalize Single Packet Authorization (SPA) as implemented by the fwknop project to most cloud computing environments subject to certain requirements. Cloud … More →

    newswww.helpnetsecurity.comApr 8, 2013, 6:22 AM
  • It has been close to four years since the birth of the Microsoft Active Protections Program (MAPP). The program is meant to give security vendors vulnerability information early so that they can provide updated protections to customers, and up until recently, seems to have functioned without a hitch.

    newswww.securityweek.comMar 19, 2012, 10:10 PM
  • Luigi Auriemma, the researcher who discovered a recently patched critical vulnerability in Microsoft’s Remote Desktop Protocol (RDP), published a proof-of-concept exploit for it after a separate working exploit, which he said possibly originated from Microsoft, was leaked online on Friday. Identified as CVE-2012-0002 and patched by Microsoft on Tuesday, the critical vulnerability can be exploited […]

    newswww.csoonline.comMar 16, 2012, 3:00 PM
  • Microsoft today released six security updates that patched seven vulnerabilities, including a critical Windows bug that hackers will certainly try to exploit with a network worm, according to researchers. “This is a pre-authentication, remote code bug,” said Andrew Storms, director of security operations at nCircle Security, referring to MS12-020, the one critical bulletin today and […]

    newswww.csoonline.comMar 13, 2012, 3:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence