A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHuawei Agile Controller Campus
HWHuaweiall versionsHuawei Agile Controller Campus Firmware
OSHuaweiv100r002c00v100r002c10Huawei Bh620 V2
HWHuaweiall versionsHuawei Bh620 V2 Firmware
OSHuaweiv100r002c00Huawei Bh621 V2
HWHuaweiall versionsHuawei Bh621 V2 Firmware
OSHuaweiv100r002c00Huawei Bh622 V2
HWHuaweiall versionsHuawei Bh622 V2 Firmware
OSHuaweiv100r001c00Huawei Bh640 V2
HWHuaweiall versionsHuawei Bh640 V2 Firmware
OSHuaweiv100r002c00Huawei Ch121
HWHuaweiall versionsHuawei Ch121 Firmware
OSHuaweiv100r001c00Huawei Ch140
HWHuaweiall versionsHuawei Ch140 Firmware
OSHuaweiv100r001c00Huawei Ch220
HWHuaweiall versionsHuawei Ch220 Firmware
OSHuaweiv100r001c00Huawei Ch221
HWHuaweiall versionsHuawei Ch221 Firmware
OSHuaweiv100r001c00Huawei Ch222
HWHuaweiall versionsHuawei Ch222 Firmware
OSHuaweiv100r002c00Huawei Ch240
HWHuaweiall versionsHuawei Ch240 Firmware
OSHuaweiv100r001c00Huawei Ch242
HWHuaweiall versionsHuawei Ch242 Firmware
OSHuaweiv100r001c00Huawei Ch242 V3
HWHuaweiall versionsHuawei Ch242 V3 Firmware
OSHuaweiv100r001c00Huawei E6000
HWHuaweiall versionsHuawei E6000 Chassis
HWHuaweiall versionsHuawei E6000 Chassis Firmware
OSHuaweiv100r001c00Huawei E6000 Firmware
OSHuaweiv100r002c00
CISA KEV — detailsi
- Vendori
- Microsoft ↗
- Producti
- Remote Desktop Services
- Added to KEVi
- November 3, 2021
- Remediation deadline (US Federal)i
- May 3, 2022(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Apply updates per vendor instructions.
Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.
Related vulnerabilities
RCE w Windows DNS Server — krytyczna podatność SIGRed (CVSS 10.0)
RCE w Hyper-V RemoteFX vGPU — błąd walidacji wejścia od gościa
RCE w Microsoft .NET Framework — nieprawidłowa walidacja danych wejściowych
RCE w Windows Search — przejęcie kontroli nad systemem
RCE w HTTP.sys — zdalne wykonanie kodu w Windows przez spreparowane żądania HTTP