Vulnerability Description
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows 7 | - |
| Microsoft | Windows Server 2008 | - |
| Siemens | Axiom Multix M Firmware | All versions |
| Siemens | Axiom Multix M | - |
| Siemens | Axiom Vertix Md Trauma Firmware | All versions |
| Siemens | Axiom Vertix Md Trauma | - |
| Siemens | Axiom Vertix Solitaire M Firmware | All versions |
| Siemens | Axiom Vertix Solitaire M | - |
| Siemens | Mobilett Xp Digital Firmware | All versions |
| Siemens | Mobilett Xp Digital | - |
| Siemens | Multix Pro Acss P Firmware | All versions |
| Siemens | Multix Pro Acss P | - |
| Siemens | Multix Pro P Firmware | All versions |
| Siemens | Multix Pro P | - |
| Siemens | Multix Pro Firmware | All versions |
| Siemens | Multix Pro | - |
| Siemens | Multix Pro Acss Firmware | All versions |
| Siemens | Multix Pro Acss | - |
| Siemens | Multix Pro Navy Firmware | All versions |
| Siemens | Multix Pro Navy | - |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/153133/Microsoft-Windows-Remote-Desktop-BluExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/153627/Microsoft-Windows-RDP-BlueKeep-DeniaExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/154579/BlueKeep-RDP-Remote-Windows-Kernel-UExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/155389/Microsoft-Windows-7-x86-BlueKeep-RDPThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/162960/Microsoft-RDP-Remote-Code-Execution.ExploitThird Party AdvisoryVDB Entry
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190529-01-windowsThird Party Advisory
- http://www.huawei.com/en/psirt/security-notices/huawei-sn-20190515-01-windows-enThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-166360.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-406175.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-433987.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-616199.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-832947.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-932041.pdfThird Party Advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708PatchVendor Advisory
- http://packetstormsecurity.com/files/153133/Microsoft-Windows-Remote-Desktop-BluExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2019-0708?
CVE-2019-0708 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially...
How severe is CVE-2019-0708?
CVE-2019-0708 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-0708?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows 7, Microsoft Windows Server 2008, Siemens Axiom Multix M Firmware, Siemens Axiom Multix M, Siemens Axiom Vertix Md Trauma Firmware.