VulnerabilityAnalyzed
CVE-2019-0708
Microsoft Remote Desktop Services Remote Code Execution Vulnerability
KEVCRITICAL 9.8EPSS 100.0%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 100.00% probability · 100th percentile
- CISA KEV
- Listed 3 November 2021 · due 3 May 2022 · used in ransomware campaigns
- Weakness
- CWE-416
- Affected
- microsoft/windows 7 · microsoft/windows server 2008 · siemens/axiom multix m firmware · siemens/axiom vertix md trauma firmware · siemens/axiom vertix solitaire m firmware · siemens/mobilett xp digital firmware · siemens/multix pro acss p firmware · siemens/multix pro p firmware · siemens/multix pro firmware · siemens/multix pro acss firmware · siemens/multix pro navy firmware · siemens/multix swing firmware · siemens/multix top firmware · siemens/multix top acss firmware · siemens/multix top p firmware · siemens/multix top acss p firmware · siemens/vertix solitaire firmware · siemens/atellica solution firmware · siemens/aptio firmware · siemens/streamlab firmware · +40 more
- Source
- secure@microsoft.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-0708
References
- http://packetstormsecurity.com/files/153133/Microsoft-Windows-Remote-Desktop-BlueKeep-Denial-Of-Service.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/153627/Microsoft-Windows-RDP-BlueKeep-Denial-Of-Service.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/154579/BlueKeep-RDP-Remote-Windows-Kernel-Use-After-Free.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/155389/Microsoft-Windows-7-x86-BlueKeep-RDP-Use-After-Free.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/162960/Microsoft-RDP-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190529-01-windows-enThird Party Advisory
- http://www.huawei.com/en/psirt/security-notices/huawei-sn-20190515-01-windows-enThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-166360.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-406175.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-433987.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-616199.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-832947.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-932041.pdfThird Party Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708Patch, Vendor Advisory
- http://packetstormsecurity.com/files/153133/Microsoft-Windows-Remote-Desktop-BlueKeep-Denial-Of-Service.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/153627/Microsoft-Windows-RDP-BlueKeep-Denial-Of-Service.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/154579/BlueKeep-RDP-Remote-Windows-Kernel-Use-After-Free.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/155389/Microsoft-Windows-7-x86-BlueKeep-RDP-Use-After-Free.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/162960/Microsoft-RDP-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190529-01-windows-enThird Party Advisory
- http://www.huawei.com/en/psirt/security-notices/huawei-sn-20190515-01-windows-enThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-166360.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-406175.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-433987.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-616199.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-832947.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-932041.pdfThird Party Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708Patch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0708US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.