RDPSoft

Remote Desktop and Terminal Server Software

We Monitor, Manage & Fix RDS, AVD, Citrix and Parallels RAS
  • Products / Services
    • Not Sure Where To Start?
    • The Complete Monitoring and Management Bundle For End User Computing
    • RDS / AVD Monitoring & Reporting
      • Remote Desktop Commander Suite
      • Sysmundo
    • RDS / AVD Management and RMM Tools
      • Remote Desktop Commander Lite (Free RDS/AVD Management Tool)
      • Remote Assistance RMM Tool + Delegation of Management for RDS/AVD Support Desk
      • Automatic Resolution of Locked Profiles and Stuck Sessions
    • RDS/AVD Synthetic Login Monitoring / Connection Time / Uptime Monitoring Tools
      • Remote Desktop Canary
    • RDS/AVD/Citrix Profile and Session Problem Remediation
      • Fix My Session
    • Digital Forensics and Incident Response Tools
      • Sysmundo
    • Consulting and Professional Services
      • RDS Performance Audits, Security Audits, and General RDS Consulting
      • Custom Report Design Services
      • Training and Other Professional Services
  • Download
    • RDC Lite: Free RDS/Citrix Session and Farm Manager
    • RDC Lite With Premium Management Features
    • RDC Suite: Installer and Release Notes
    • Remote Desktop Canary – Request a Demo/Trial
    • Sysmundo
    • Request Upgrade To New Version
  • Buy
    • The Complete RDS/AVD Monitoring and Management Bundle Purchase Options
      • Start Monthly Subscription Now
      • Start Annual Subscription Now
    • Remote Desktop Commander Suite Purchase Options
      • Start Monthly Subscription Now
      • Start Annual Subscription Now
    • Premium Management Features Purchase Options
      • Start Monthly Subscription Now
      • Start Annual Subscription Now
    • Remote Desktop Canary Purchase Options
      • Start Monthly Subscription Now
      • Start Annual Subscription Now
    • Fix My Session Purchase Options
      • Start Monthly Subscription Now
      • Start Annual Subscription Now
    • Sysmundo Purchase Options
      • Start Monthly Subscription Now
      • Start Annual Subscription Now
    • Buy Incident Based Support Packages
    • Pricing
  • Blog
  • Support
    • Contact Support / Submit Ticket
    • RDPSoft Knowledge Base
  • Contact
  • Partners

Remote Desktop Commander Suite RDCCrd.exe Utility Vulnerability

Background: A European security professional, Jose Magalhaes of the NATO Cyber Security Centre, contacted us recently to let us know that he discovered both a SQL injection and weak permissions vulnerability that affect the specialized RDCCrd.exe tool that ships with the Remote Desktop Commander Suite. The RDCCrd.exe tool is a CReate/Update/Delete utility that allows administrators to change things like the servers monitored by our software, scheduled reports, etc programmatically as opposed to using the Remote Desktop Commander Configuration Tool GUI. Upon further research, we verified these vulnerabilities exist in Remote Desktop Commander v6.0 and earlier versions.

Severity: Based on our internal research, we think the general exploitability of these vulnerabilities are LOW for the vast majority of deployments of our software. In most customer deployments, the Remote Desktop Commander Suite components are installed to a Windows Server with access only by systems administrators, not ordinary users.

However, in deployments where the main Remote Desktop Commander Suite application:

  • Is installed directly on one or more terminal server session hosts AND,
  • Where the administrator has configured our software to use Standard SQL authentication to communicate with its SQL database, as opposed to Windows Integrated Authentication,

a standard, non-admin user could potentially abuse this vulnerability to read, alter, or remove the data our software collects into its database.

Please note that this vulnerability DOES NOT affect RDS servers in your deployment where you have ONLY installed the Remote Desktop Commander Agent, as opposed to the entire Remote Desktop Commander Suite application.

In all deployment scenarios, though, we recommend that our customers upgrade to Version 6.5 of the Remote Desktop Commander Suite, which both fixes the SQL Injection vulnerability and sets default NTFS permissions on the Tools subdirectory that houses the RDCCrd.exe application so that only Administrators can access it.

What is a SQL Injection Vulnerability?

Broadly, SQL Injection is a type of vulnerability where an attacker can place unexpected parameters or specialized syntax into the underlying database query that a program is making to insert, retrieve, update, or delete from its database. When successful, an attacker can read, alter, or remove data from the underlying program’s database.

What is a Weak Permissions Vulnerability?

A weak registry or file system permissions vulnerability allows a standard user to read information and/or execute programs they may not need access to, which in certain cases can lead to additional exploits being leveraged to attack a system.

How Do I Mitigate This Vulnerability?

If you are a current monthly or annual subscription customer to the Remote Desktop Commander Suite, OR you are a perpetual license customer with an active maintenance agreement, request an upgrade to Version 6.5 of the Remote Desktop Commander Suite here:

https://www.rdpsoft.com/upgrade

If you are a perpetual license customer with an expired maintenance agreement, you can change the NTFS permissions on the \Program Files (x86)\RDPSoft\Remote Desktop Commander\Tools subfolder so that only Administrators have access to programs in this directory.

I Have Deployed the Remote Desktop Commander Suite Directly on a Remote Desktop or AVD Session Host Where Standard Users Regularly Connect and Run Programs. How Can I Further Tighten Security On Your Application?

You can take the following additional steps:

1.) Change the NTFS permissions on the following files and folders located under the \Program Files (x86)\RDPSoft\Remote Desktop Commander directory so that only Administrators can read and execute them:

  • RDPRDRLic.exe
  • RDPReporterClient.exe
  • RDPReporterService.exe
  • RDPReporterSPLT.exe
  • RDRSQLDBCreator.exe
  • RDSConfig.exe
  • RDSLogViewer.exe
  • AgentInstaller folder
  • ClientInstaller folder
  • ImageRepository folder
  • PowerShellScripts folder
  • ScheduledReports folder
  • Tools folder

2.) Change the NTFS permissions on the following registry key so that only local Administrators can read and modify it and its values:

HKLM\Software\Wow6432Node\RDPReporter

We’re Here If You Need Us

If you have any questions about the above vulnerabilities or whether or not your deployment of our software may be affected, please reach out to us by starting a new support ticket here, and we’ll be happy to assist you.

  • Email
  • LinkedIn
  • Twitter
  • YouTube

Not Sure Where To Start?

In just a few moments, you can find the right fit of solutions and even services for your needs.

> Get Going Now.

Help Documents

Remote Desktop Commander
Help and Users Guide
Release Notes (ver 8.x)

Sign Up for Remote Desktop Tips and RDPSoft Updates

Blog Topic Categories

  • Azure RemoteApp
  • Azure Virtual Desktop
  • citrix edgesight
  • Citrix Edgesight Replacement
  • Citrix Shadowing
  • Cloud RDP Monitoring
  • DEX
  • Performance
  • RDP Disconnects
  • RDP Latency
  • RDP Login Time
  • RDP Login Tracking
  • RDP Logon Failure Tracking
  • RDP Logs
  • RDP Loss Rate
  • RDP Security
  • RDP Transmission Rate
  • RDS Infrastructure
  • RDS License Metering
  • RDS Licensing
  • Remote Desktop Bandwidth
  • Remote Desktop CPU
  • Remote Desktop Management
  • Remote Desktop Memory
  • Remote Desktop Memory Usage
  • Remote Desktop Monitoring
  • Remote Desktop Performance
  • Remote Desktop Protocol
  • Remote Desktop Reporting
  • Remote Desktop Security
  • Remote Desktop Services
  • Remote Desktop Services Free Tools
  • Remote Desktop Services Hotfix
  • Sensitive Data
  • Server 2012 TSAdmin Replacement
  • Shadow User
  • Software Releases
  • SPLA Reporting
  • Synthetic RDP
  • Sysmon
  • Telecommuting/Teleworking
  • Terminal Server Logging
  • Terminal Server Monitoring
  • Uncategorized
  • User Activity Monitoring
  • User Productivity
  • User Profiles
  • Windows 2008 Terminal Server
  • Windows Virtual Desktop
  • WVD Login Time
  • XenApp Monitoring
  • XenApp Reporting

Recent Posts

  • DEX Monitoring for AVD
  • Remote Desktop User Activity Monitoring
  • Remote Desktop Commander Suite v8 Now Available!
  • Remote Desktop Commander Suite v8 Beta Details, Plus a New Solution to Limit Local Admin Rights in EUC
  • Fix My Session v1 Now Available!

From the RDPSoft Blog

  • DEX Monitoring for AVD
  • Remote Desktop User Activity Monitoring
  • Remote Desktop Commander Suite v8 Now Available!
  • Remote Desktop Commander Suite v8 Beta Details, Plus a New Solution to Limit Local Admin Rights in EUC
  • Fix My Session v1 Now Available!
  • Email
  • LinkedIn
  • Twitter
  • YouTube

We Do “Single Pane of Glass” Monitoring and Management for RDS

Top Level Deployment Dashboard

One of the biggest criticisms leveled against Microsoft's Remote Desktop Services as an end user computing (EUC) platform is its complete lack of integrated management and monitoring tools. … Learn more about our centralized RDS monitoring and management >

Reach Out

For fastest response, reach out via our sales and support contact forms.

Sales
US: 1-855-738-8457 x1
Outside the US: 1-702-749-4325 x1

Support
for Evaluators and Priority Support Customers
US: 1-855-738-8457 x2
Outside the US: 1-702-749-4325 x2

© Copyright 2013–2026 RDPSoft. All Rights Reserved. RDPSoft is the sole authorized publisher and distributor of the following software titles: Remote Desktop Commander, Premium Management Features, Remote Desktop Canary · Sitemap