Remote Desktop Protocol Vulnerability MS12-020
Originally Published: 2015-09-07
Last Modified: 2023-09-24
Article Number
Applies To
CVE Identifier(s)
Operating System
Alert Impact
Impacted - Apply Vendor Remedy
Alert Impact Explanation
Actually we have listed this patch in our monthly enVision OS Updates list when released on March 2012 and suggested customer to apply it:
RSA enVision OS Updates - Windows 2003 SP1/SP2 Enterprise 64-bit
https://knowledge.rsasecurity.com/scolcms/set.aspx?id=5353
https://knowledge.rsasecurity.com/docs/rsa_env/osupdates/2012/win2003-64/Mar2012-win2003-64.htm
https://knowledge.rsasecurity.com/docs/rsa_env/osupdates/2012/win2008-64/4.1SP1-Win2008-64bit.htm
Because this issue only impacts on windows system but not enVision appliances thus please take the suggestion in MSFT bulletin.
You can find the latest download link of that patch from link below , under section “Affected and Non-Affected Software”:
Microsoft Security Bulletin MS12-020 - Critical
http://technet.microsoft.com/en-us/security/bulletin/ms12-020
Meanwhile, because our envision windows installation image was created on 2011 and a lot of new patches for windows has been related monthly by MSFT since that thus we suggest customer to monitor our RSA OS Updates list over SCOL site and apply these listed patches which has been verified first by RSA in order to keep our server in protected and this operation has been included in envision administrator’s guide (see attachment ) and you can also find the full version from our SCOL site regarding other recommended operations:
https://knowledge.rsasecurity.com/docs/rsa_env/envision/41sp1/enVision_admin_guide.pdf
Notes
Windows Server 2003 x64 Edition Service Pack 2 (KB2621440)
http://www.microsoft.com/downloads/details.aspx?familyid=8081e67f-288c-4714-bff8-e0ff9777692f
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (KB2621440 and KB2667402)
http://www.microsoft.com/downloads/details.aspx?familyid=40b62d08-d2a2-4900-b01c-46fc761973d0
http://www.microsoft.com/downloads/details.aspx?familyid=7ec21f41-1673-4592-b45c-6438ad57e08c
***Update package KB2621440 addresses CVE-2012-0002 and update package KB2667402 addresses CVE-2012-0152. While CVE-2012-0152 has a lower severity rating than KB2621440 on affected versions of Microsoft Windows, the aggregate severity rating is Critical based on CVE-2012-0002. Customers should apply all updates offered for the version of Microsoft Windows installed on their systems.
Disclaimer
Related Articles
How does Remote Desktop handle Smart card and NLA? 75Number of Views Report preview and/or generation fails with 'java.lang.NoClassDefFoundError: Could not initialize class net.sf.jasperrepor… 265Number of Views RSA Authentication Manager 8.2 backup fails when backing up system files after promoting replica to primary 818Number of Views Report preview and/or generation fails with 'java.lang.NoClassDefFoundError: Could not initialize class net.sf.jasperrepor… 475Number of Views RSA Cloud Access Service Shows Partial Publish Failure After Configuring REST Agent Connection to RSA Authentication Manager 216Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?