Microsoft Windows Remote Desktop Services CVE-2019-0708 Remote Code Execution Vulnerability
BID:108273
Info
Microsoft Windows Remote Desktop Services CVE-2019-0708 Remote Code Execution Vulnerability
| Bugtraq ID: | 108273 |
| Class: | Design Error |
| CVE: |
CVE-2019-0708 |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 2019 12:00AM |
| Updated: | Jun 18 2019 02:00PM |
| Credit: | The UK's National Cyber Security Centre (NCSC) |
| Vulnerable: |
Microsoft Windows XP 0 Microsoft Windows Server 2008 R2 for x64-based Systems SP1 Microsoft Windows Server 2008 R2 for Itanium-based Systems SP1 Microsoft Windows Server 2008 for x64-based Systems SP2 Microsoft Windows Server 2008 for Itanium-based Systems SP2 Microsoft Windows Server 2008 for 32-bit Systems SP2 Microsoft Windows Server 2003 0 Microsoft Windows 7 for x64-based Systems SP1 Microsoft Windows 7 for 32-bit Systems SP1 |
| Not Vulnerable: | |
Discussion
Microsoft Windows Remote Desktop Services CVE-2019-0708 Remote Code Execution Vulnerability
Microsoft Windows is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the affected application. Failed attacks will cause denial-of-service conditions.
Microsoft Windows is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the affected application. Failed attacks will cause denial-of-service conditions.
Exploit / POC
Microsoft Windows Remote Desktop Services CVE-2019-0708 Remote Code Execution Vulnerability
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
Microsoft Windows Remote Desktop Services CVE-2019-0708 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Microsoft Windows Remote Desktop Services CVE-2019-0708 Remote Code Execution Vulnerability
References:
References:
- Proof of concept for CVE-2019-0708 (Github)
- Microsoft Homepage (Microsoft)
- Microsoft Windows Homepage (Microsoft )
- AA19-168A Microsoft Operating Systems BlueKeep Vulnerability (US-CERT)
- CVE-2019-0708 | Remote Desktop Services Remote Code Execution Vulnerability (Microsoft)
- Prevent a worm by updating Remote Desktop Services (CVE-2019-0708) (Microsoft)