CVE-2019-0708Critical KEVConfirmedExploit available
MSR
MSR
Microsoft Security Response Center
The Security Update Guide is the source of truth for vulnerabilities in Microsoft products — KB article numbers, impacted builds and replacement patches. MSRC also assigns the MSRC-specific exploitability index used alongside CVSS.
Region
US
Updates
Patch Tuesday + ad-hoc
License
Proprietary
Microsoft's Security Update Guide, covering Windows, Office, Azure, SQL Server, Exchange and other first-party products.
https://msrc.microsoft.com/update-guide →Share link
Anyone with the link can open this vulnerability.
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacke…
CVSS
9.8
Critical
EPSS
0.94
p99
Published
2019-01-01
Updated
2021-11-03
Description
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
Tags · CWE
KEVRCEPre-auth
CWE-416
CWE-416VariantStable
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
https://cwe.mitre.org/data/definitions/416.html →Open in CWE collection →Affected products
Agile_controller-campus_firmwareAptio_firmwareAtellica_solution_firmwareAxiom_multix_m_firmwareAxiom_vertix_md_trauma_firmwareAxiom_vertix_solitaire_m_firmwareBh620_v2_firmwareBh621_v2_firmwareBh622_v2_firmwareBh640_v2_firmwareCentralink_firmwareCh121_firmwareCh140_firmwareCh220_firmwareCh221_firmwareCh222_firmwareCh240_firmwareCh242_firmwareCh242_v3_firmwareE6000_chassis_firmware
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2019-01-01
Published
2021-11-03
Added to KEV
2021-11-03
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.945 · p99
Known exploited (KEV)
Yes
Known exploits — Сканер-ВС
CVE-2019-0708
cisa · https://www.cisa.gov/known-exploited-vulnerabilities-catalog
46946
exploitdb · https://www.exploit-db.com/exploits/46946
47120
exploitdb · https://www.exploit-db.com/exploits/47120
47416
exploitdb · https://www.exploit-db.com/exploits/47416
47683
exploitdb · https://www.exploit-db.com/exploits/47683
Affected software
| Product | Vendor | Status |
|---|---|---|
| agile_controller-campus_firmware | * | Exploited |
| aptio_firmware | * | Exploited |
| atellica_solution_firmware | * | Exploited |
| axiom_multix_m_firmware | * | Exploited |
| axiom_vertix_md_trauma_firmware | * | Exploited |
| axiom_vertix_solitaire_m_firmware | * | Exploited |
| bh620_v2_firmware | * | Exploited |
| bh621_v2_firmware | * | Exploited |
| bh622_v2_firmware | * | Exploited |
| bh640_v2_firmware | * | Exploited |
| centralink_firmware | * | Exploited |
| ch121_firmware | * | Exploited |
| ch140_firmware | * | Exploited |
| ch220_firmware | * | Exploited |
| ch221_firmware | * | Exploited |
| ch222_firmware | * | Exploited |
| ch240_firmware | * | Exploited |
| ch242_firmware | * | Exploited |
| ch242_v3_firmware | * | Exploited |
| e6000_chassis_firmware | * | Exploited |
Source databases
MSR
MSR
Microsoft Security Response Center
The Security Update Guide is the source of truth for vulnerabilities in Microsoft products — KB article numbers, impacted builds and replacement patches. MSRC also assigns the MSRC-specific exploitability index used alongside CVSS.
Region
US
Updates
Patch Tuesday + ad-hoc
License
Proprietary
Microsoft's Security Update Guide, covering Windows, Office, Azure, SQL Server, Exchange and other first-party products.
https://msrc.microsoft.com/update-guide →CVE
CVE
National Vulnerability Database
NVD is the U.S. government repository of standards-based vulnerability management data, built on top of the MITRE CVE list. Every record includes CPE applicability statements, CVSS v2 and v3.x base scores, CWE mappings and cross-references to advisories.
Region
US
Updates
15 min
License
Public Domain
Comprehensive catalog of publicly disclosed vulnerabilities with CPE matches, CVSS scoring and reference URLs. De-facto standard for cross-vendor correlation.
https://nvd.nist.gov →Related vulnerabilities