peter bassill · operator
$ cve CVE-2019-0708 JSON

CVE-2019-0708 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS100% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-416
On CISA KEVyes — remediate by 2022-05-03
Public exploityes
Published2019-05-16
Last modified2026-06-17

CISA KEV

NameMicrosoft Remote Desktop Services Remote Code Execution Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productMicrosoft / Remote Desktop Services
Ransomware useknown

Affected (40)

VendorProduct
microsoftwindows 7
microsoftwindows server 2008
siemensaptio
siemensaptio firmware
siemensatellica solution
siemensatellica solution firmware
siemensaxiom multix m
siemensaxiom multix m firmware
siemensaxiom vertix md trauma
siemensaxiom vertix md trauma firmware
siemensaxiom vertix solitaire m
siemensaxiom vertix solitaire m firmware
siemenscentralink
siemenscentralink firmware
siemensmobilett xp digital
siemensmobilett xp digital firmware
siemensmultix pro
siemensmultix pro acss
siemensmultix pro acss firmware
siemensmultix pro acss p
siemensmultix pro acss p firmware
siemensmultix pro firmware
siemensmultix pro navy
siemensmultix pro navy firmware
siemensmultix pro p
siemensmultix pro p firmware
siemensmultix swing
siemensmultix swing firmware
siemensmultix top
siemensmultix top acss
siemensmultix top acss firmware
siemensmultix top acss p
siemensmultix top acss p firmware
siemensmultix top firmware
siemensmultix top p
siemensmultix top p firmware
siemensstreamlab
siemensstreamlab firmware
siemensvertix solitaire
siemensvertix solitaire firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD