Skip to main content

Posts

Showing posts from 2018

Unable to RDP From Windows 7: Encryption Oracle Remediation

Remote Desktop Authentication Error Has Occurred. The function requested is not supported. With the release of the March 2018 Security bulletin, there was a fix that addressed a CredSSP, “Remote Code Execution” vulnerability (CVE-2018-0886) which could impact RDP connections. The vulnerability was discovered to which the exploits observed were: Targets receive a malicious RTF Microsoft Office document After being opened, the malicious document causes the second stage of the exploit to be downloaded in the form of an HTML page with malicious code The malicious code triggers the use-after-free memory-corruption bug Accompanying shellcode then downloads and executes a malicious payload Symptoms 1.       The VM screenshot shows the OS fully loaded and waiting for the credentials 2.       If you try to RDP the VM either internally or externally, you'll get the message: An authentication error has occurred. The function requested is not supported. This coul