SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2019-0708

Microsoft Remote Desktop Services Remote Code Execution Vulnerability

KEVCRITICAL 9.8EPSS 100.0%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
100.00% probability · 100th percentile
CISA KEV
Listed 3 November 2021 · due 3 May 2022 · used in ransomware campaigns
Weakness
CWE-416
Affected
microsoft/windows 7 · microsoft/windows server 2008 · siemens/axiom multix m firmware · siemens/axiom vertix md trauma firmware · siemens/axiom vertix solitaire m firmware · siemens/mobilett xp digital firmware · siemens/multix pro acss p firmware · siemens/multix pro p firmware · siemens/multix pro firmware · siemens/multix pro acss firmware · siemens/multix pro navy firmware · siemens/multix swing firmware · siemens/multix top firmware · siemens/multix top acss firmware · siemens/multix top p firmware · siemens/multix top acss p firmware · siemens/vertix solitaire firmware · siemens/atellica solution firmware · siemens/aptio firmware · siemens/streamlab firmware · +40 more
Source
secure@microsoft.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-0708

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.