# Users are not able to connect to RDP application with SNX in Application Mode

**Product**: Mobile Access / SSL VPN  
**Version**: R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20  
**OS**: Gaia, Windows  
**Platform**: All  
**Last Modified**: 2024-03-13

## Symptoms

- RDP does not work with SSL Network Extender (SNX) in Application Mode.
- In the STALog.txt (from sk104577, under "SNX client in Application Mode on Windows OS"):
  
  ```
  [ ...][DATE TIME][apijack] apijack_CreateProcessW: flags=0x14 AppName:C:\WINDOWS\system32\mstsc.exe, CommandLine:c:\windows\\System32\\mstsc.exe /v 10.10.10.10
  [ ...][DATE TIME][apijack] apijack_LoadLibraryExW: ntdll.dll - new ver
  [ ...][DATE TIME][apijack] apijack_should_hook_module: calling apijack_extract_module_name
  [ ...][DATE TIME][apijack] apijack_should_hook_module: module - C:\WINDOWS\SYSTEM32\ntdll.dll
  [ ...][DATE TIME][apijack] apijack_is_already_hooked: C:\WINDOWS\SYSTEM32\ntdll.dll already hooked
  [ ...][DATE TIME][apijack] apijack_GetProcAddress: Called - new ver
  [ ...][DATE TIME][apijack] apijack_GetProcAddress: modname=C:\WINDOWS\SYSTEM32\ntdll.dll, pszProcName=7726458c
  [ ...][DATE TIME][apijack] apijack_GetProcAddress: Load by name RtlGetNtSystemRoot
  [ ...][DATE TIME][apijack] apijack_GetProcAddress: Go get hook
  [ ...][DATE TIME][apijack] apijack_GetProcAddress: Check for notify procaddr
  [ ...][DATE TIME][apijack] apijack_GetProcAddress: return address: 77590270
  [ ...][DATE TIME][apijack] apijack_inject_to_process: failed to obtain thread context data: Falscher Parameter.
  [ ...][DATE TIME][apijack] apijack_CreateProcessW: failed to inject code into process id (5732)
  ```

## Solution

This problem was fixed. The fix is included in:

- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 43
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 113
- [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 89
- [Jumbo Hotfix Accumulator for R80.40](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm) starting from Take 211

If you choose not to upgrade, Check Point can supply a **Hotfix**. [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**

Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

#### NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
