CVE-2019-0708

EUVD-2019-1468
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
microsoftwindows_7
-
microsoftwindows_server_2008
-
siemensaxiom_multix_m_firmware
*
siemensaxiom_vertix_md_trauma_firmware
*
siemensaxiom_vertix_solitaire_m_firmware
*
siemensmobilett_xp_digital_firmware
*
siemensmultix_pro_acss_p_firmware
*
siemensmultix_pro_p_firmware
*
siemensmultix_pro_firmware
*
siemensmultix_pro_acss_firmware
*
siemensmultix_pro_navy_firmware
*
siemensmultix_swing_firmware
*
siemensmultix_top_firmware
*
siemensmultix_top_acss_firmware
*
siemensmultix_top_p_firmware
*
siemensmultix_top_acss_p_firmware
*
siemensvertix_solitaire_firmware
*
siemensatellica_solution_firmware
*
siemensaptio_firmware
*
siemensstreamlab_firmware
*
siemenscentralink_firmware
*
siemensviva_e_firmware
*
siemensviva_twin_firmware
*
siemenssyngo_lab_process_manager
*
siemensrapidpoint_500_firmware
𝑥
≤ 2.3.2
siemenslantis_firmware
*
𝑥
= Vulnerable software versions
Windows Releases
Platform
Version
Windows 7
Service Pack 1 (x64, x86)
Windows Server 2008
Service Pack 2 (x64, x86)
Service Pack 2 Server Core (x64, x86)
Windows Server 2008 R2
Service Pack 1 (x64)
Service Pack 1 Server Core (x64)
References