CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2019-0708

CVSS 9.8v3.1pub. 2019-05-16upd. 2025-10-29

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Huawei Agile Controller Campus

    HW
    Huawei
    all versions
  • Huawei Agile Controller Campus Firmware

    OS
    Huawei
    v100r002c00v100r002c10
  • Huawei Bh620 V2

    HW
    Huawei
    all versions
  • Huawei Bh620 V2 Firmware

    OS
    Huawei
    v100r002c00
  • Huawei Bh621 V2

    HW
    Huawei
    all versions
  • Huawei Bh621 V2 Firmware

    OS
    Huawei
    v100r002c00
  • Huawei Bh622 V2

    HW
    Huawei
    all versions
  • Huawei Bh622 V2 Firmware

    OS
    Huawei
    v100r001c00
  • Huawei Bh640 V2

    HW
    Huawei
    all versions
  • Huawei Bh640 V2 Firmware

    OS
    Huawei
    v100r002c00
  • Huawei Ch121

    HW
    Huawei
    all versions
  • Huawei Ch121 Firmware

    OS
    Huawei
    v100r001c00
  • Huawei Ch140

    HW
    Huawei
    all versions
  • Huawei Ch140 Firmware

    OS
    Huawei
    v100r001c00
  • Huawei Ch220

    HW
    Huawei
    all versions
  • Huawei Ch220 Firmware

    OS
    Huawei
    v100r001c00
  • Huawei Ch221

    HW
    Huawei
    all versions
  • Huawei Ch221 Firmware

    OS
    Huawei
    v100r001c00
  • Huawei Ch222

    HW
    Huawei
    all versions
  • Huawei Ch222 Firmware

    OS
    Huawei
    v100r002c00
  • Huawei Ch240

    HW
    Huawei
    all versions
  • Huawei Ch240 Firmware

    OS
    Huawei
    v100r001c00
  • Huawei Ch242

    HW
    Huawei
    all versions
  • Huawei Ch242 Firmware

    OS
    Huawei
    v100r001c00
  • Huawei Ch242 V3

    HW
    Huawei
    all versions
  • Huawei Ch242 V3 Firmware

    OS
    Huawei
    v100r001c00
  • Huawei E6000

    HW
    Huawei
    all versions
  • Huawei E6000 Chassis

    HW
    Huawei
    all versions
  • Huawei E6000 Chassis Firmware

    OS
    Huawei
    v100r001c00
  • Huawei E6000 Firmware

    OS
    Huawei
    v100r002c00

CISA KEV — detailsi

Vendori
Microsoft
Producti
Remote Desktop Services
Added to KEVi
November 3, 2021
Remediation deadline (US Federal)i
May 3, 2022(overdue)
Ransomwarei
Active ransomware campaigns exploit this vulnerability
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
☠️WYKORZYSTYWANE W RANSOMWARECISA DEADLINE: 3 maja 2022
Tags
RCEAuth BypassMemory
CWE
References

Related vulnerabilities

CVE-2020-1350CRITICAL10.0⚠ KEVPL ✓same product

RCE w Windows DNS Server — krytyczna podatność SIGRed (CVSS 10.0)

CVE-2020-1040CRITICAL9.0⚠ KEVPL ✓same product

RCE w Hyper-V RemoteFX vGPU — błąd walidacji wejścia od gościa

CVE-2020-0646CRITICAL9.8⚠ KEVPL ✓same product

RCE w Microsoft .NET Framework — nieprawidłowa walidacja danych wejściowych

CVE-2017-8543CRITICAL9.8⚠ KEVPL ✓same product

RCE w Windows Search — przejęcie kontroli nad systemem

CVE-2015-1635CRITICAL9.8⚠ KEVPL ✓same product

RCE w HTTP.sys — zdalne wykonanie kodu w Windows przez spreparowane żądania HTTP