10

CVE-2019-0708

Warning
Exploit

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftWindows 7 Version- Updatesp1
MicrosoftWindows Server 2008 Version- Updatesp2
MicrosoftWindows Server 2008 Versionr2 Updatesp1
SiemensAptio Firmware
   SiemensAptio Version-
SiemensStreamlab Firmware
   SiemensStreamlab Version-
SiemensViva E Firmware
   SiemensViva E Version-
SiemensViva Twin Firmware
   SiemensViva Twin Version-
SiemensRapidpoint 500 Firmware Version <= 2.3.2
   SiemensRapidpoint 500 Version-
SiemensLantis Firmware
   SiemensLantis Version-
HuaweiAgile Controller-campus Firmware Versionv100r002c00
   HuaweiAgile Controller-campus Version-
HuaweiAgile Controller-campus Firmware Versionv100r002c10
   HuaweiAgile Controller-campus Version-
HuaweiBh620 V2 Firmware Versionv100r002c00
   HuaweiBh620 V2 Version-
HuaweiBh621 V2 Firmware Versionv100r002c00
   HuaweiBh621 V2 Version-
HuaweiBh622 V2 Firmware Versionv100r001c00
   HuaweiBh622 V2 Version-
HuaweiBh640 V2 Firmware Versionv100r002c00
   HuaweiBh640 V2 Version-
HuaweiCh121 Firmware Versionv100r001c00
   HuaweiCh121 Version-
HuaweiCh140 Firmware Versionv100r001c00
   HuaweiCh140 Version-
HuaweiCh220 Firmware Versionv100r001c00
   HuaweiCh220 Version-
HuaweiCh221 Firmware Versionv100r001c00
   HuaweiCh221 Version-
HuaweiCh222 Firmware Versionv100r002c00
   HuaweiCh222 Version-
HuaweiCh240 Firmware Versionv100r001c00
   HuaweiCh240 Version-
HuaweiCh242 Firmware Versionv100r001c00
   HuaweiCh242 Version-
HuaweiCh242 V3 Firmware Versionv100r001c00
   HuaweiCh242 V3 Version-
HuaweiE6000 Firmware Versionv100r002c00
   HuaweiE6000 Version-
HuaweiE6000 Chassis Firmware Versionv100r001c00
   HuaweiE6000 Chassis Version-
HuaweiGtsoftx3000 Firmware Versionv200r001c01spc100
   HuaweiGtsoftx3000 Version-
HuaweiGtsoftx3000 Firmware Versionv200r002c00spc300
   HuaweiGtsoftx3000 Version-
HuaweiGtsoftx3000 Firmware Versionv200r002c10spc100
   HuaweiGtsoftx3000 Version-
HuaweiOceanstor 18500 Firmware Versionv100r001c30spc300
   HuaweiOceanstor 18500 Version-
HuaweiOceanstor 18800 Firmware Versionv100r001c30spc300
   HuaweiOceanstor 18800 Version-
HuaweiOceanstor 18800f Firmware Versionv100r001c30spc300
   HuaweiOceanstor 18800f Version-
HuaweiOceanstor Hvs85t Firmware Versionv100r001c00
   HuaweiOceanstor Hvs85t Version-
HuaweiOceanstor Hvs85t Firmware Versionv100r001c30spc200
   HuaweiOceanstor Hvs85t Version-
HuaweiOceanstor Hvs88t Firmware Versionv100r001c00
   HuaweiOceanstor Hvs88t Version-
HuaweiOceanstor Hvs88t Firmware Versionv100r001c30spc200
   HuaweiOceanstor Hvs88t Version-
HuaweiRh1288 V2 Firmware Versionv100r002c00
   HuaweiRh1288 V2 Version-
HuaweiRh1288a V2 Firmware Versionv100r002c00
   HuaweiRh1288a V2 Version-
HuaweiRh2265 V2 Firmware Versionv100r002c00
   HuaweiRh2265 V2 Version-
HuaweiRh2268 V2 Firmware Versionv100r002c00
   HuaweiRh2268 V2 Version-
HuaweiRh2285 V2 Firmware Versionv100r002c00
   HuaweiRh2285 V2 Version-
HuaweiRh2285h V2 Firmware Versionv100r002c00
   HuaweiRh2285h V2 Version-
HuaweiRh2288 V2 Firmware Versionv100r002c00
   HuaweiRh2288 V2 Version-
HuaweiRh2288a V2 Firmware Versionv100r002c00
   HuaweiRh2288a V2 Version-
HuaweiRh2288e V2 Firmware Versionv100r002c00
   HuaweiRh2288e V2 Version-
HuaweiRh2288h V2 Firmware Versionv100r002c00
   HuaweiRh2288h V2 Version-
HuaweiRh2485 V2 Firmware Versionv100r002c00
   HuaweiRh2485 V2 Version-
HuaweiRh5885 V2 Firmware Versionv100r001c00
   HuaweiRh5885 V2 Version-
HuaweiRh5885 V3 Firmware Versionv100r003c00
   HuaweiRh5885 V3 Version-
HuaweiSmc2.0 Firmware Versionv500r002c00
   HuaweiSmc2.0 Version-
HuaweiSmc2.0 Firmware Versionv600r006c00
   HuaweiSmc2.0 Version-
HuaweiSeco Vsm Firmware Versionv200r002c00
   HuaweiSeco Vsm Version-
HuaweiUma Firmware Versionv200r001c00
   HuaweiUma Version-
HuaweiUma Firmware Versionv300r001c00
   HuaweiUma Version-
HuaweiX6000 Firmware Versionv100r002c00
   HuaweiX6000 Version-
HuaweiX8000 Firmware Versionv100r002c20
   HuaweiX8000 Version-
HuaweiElog Firmware Versionv200r003c10
   HuaweiElog Version-
HuaweiEspace Ecs Firmware Versionv300r001c00
   HuaweiEspace Ecs Version-

03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

Microsoft Remote Desktop Services Remote Code Execution Vulnerability

Vulnerability

Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.

Description

Apply updates per vendor instructions.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 94.45% 1
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.