Umbra Wiki cve cve/CVE-2019-0708
Back to wiki

CVE-2019-0708 — Microsoft Remote Desktop Services Remote Code Execution Vulnerability

provenance: imported · CVE: CVE-2019-0708 · CWE: CWE-416

CVE-2019-0708: Microsoft Remote Desktop Services Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Microsoft
Product Remote Desktop Services
Date added 2021-11-03
Due date 2022-05-03
Ransomware campaign use Known

Description

Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2019-0708

Weakness behind it

CISA records this vulnerability as an instance of CWE-416. From there the chain continues into CAPEC attack patterns and ATT&CK techniques, all inside this corpus.

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2019-0708
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

See all 1,746 pages under Vulnerabilities (CVE) →