CVE-2019-0708: Microsoft Remote Desktop Services Remote Code Execution Vulnerability
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
Other sources
Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0708?
The severity of CVE-2019-0708 is critical with a rating of 9.8.
How does CVE-2019-0708 impact Microsoft Remote Desktop Services?
CVE-2019-0708 allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests, resulting in remote code execution.
Which software is affected by CVE-2019-0708?
The affected software includes Microsoft Remote Desktop Services, as well as Microsoft Windows 7, Windows Server 2003, Windows Server 2008, Windows Vista, and Windows XP.
Is there a fix available for CVE-2019-0708?
Yes, Microsoft has released security updates to address the vulnerability. It is recommended to install the latest updates to mitigate the risk.
Are there any known exploits or proof-of-concept for CVE-2019-0708?
Yes, there are known exploits and proof-of-concept code available for CVE-2019-0708, highlighting the importance of applying the necessary security patches.