CVE-2019-0708
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
Affected (75)
Products: Microsoft: Windows 7, Windows Server 2008 · Siemens: Axiom Multix M Firmware, Axiom Vertix Md Trauma Firmware, Axiom Vertix Solitaire M Firmware, Mobilett Xp Digital Firmware, Multix Pro Acss P Firmware, Multix Pro P Firmware, Multix Pro Firmware, Multix Pro Acss Firmware, Multix Pro Navy Firmware, Multix Swing Firmware, Multix Top Firmware, Multix Top Acss Firmware, Multix Top P Firmware, Multix Top Acss P Firmware, Vertix Solitaire Firmware, Atellica Solution Firmware, Aptio Firmware, Streamlab Firmware, Centralink Firmware, Viva E Firmware, Viva Twin Firmware, Syngo Lab Process Manager, Rapidpoint 500 Firmware, Lantis Firmware · Huawei: Agile Controller Campus Firmware, Bh620 V2 Firmware, Bh621 V2 Firmware, Bh622 V2 Firmware, Bh640 V2 Firmware, Ch121 Firmware, Ch140 Firmware, Ch220 Firmware, Ch221 Firmware, Ch222 Firmware, Ch240 Firmware, Ch242 Firmware, Ch242 V3 Firmware, E6000 Firmware, E6000 Chassis Firmware, Gtsoftx3000 Firmware, Oceanstor 18500 Firmware, Oceanstor 18800 Firmware, Oceanstor 18800f Firmware, Oceanstor Hvs85t Firmware, Oceanstor Hvs88t Firmware, Rh1288 V2 Firmware, Rh1288a V2 Firmware, Rh2265 V2 Firmware, Rh2268 V2 Firmware, Rh2285 V2 Firmware, Rh2285h V2 Firmware, Rh2288 V2 Firmware, Rh2288a V2 Firmware, Rh2288e V2 Firmware, Rh2288h V2 Firmware, Rh2485 V2 Firmware, Rh5885 V2 Firmware, Rh5885 V3 Firmware, Smc2.0 Firmware, Seco Vsm Firmware, Uma Firmware, X6000 Firmware, X8000 Firmware, Elog Firmware, Espace Ecs Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Axiom Multix M | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Axiom Vertix Md Trauma | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Axiom Vertix Solitaire M | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Mobilett Xp Digital | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Multix Pro Acss P | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Multix Pro P | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Multix Pro | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Multix Pro Acss | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Multix Pro Navy | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Multix Swing | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Multix Top | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Multix Top Acss | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Multix Top P | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Multix Top Acss P | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Vertix Solitaire | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Atellica Solution | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Aptio | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Streamlab | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Centralink | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Viva E | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Viva Twin | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.3.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Rapidpoint 500 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Lantis | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Agile Controller Campus | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Bh620 V2 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Bh621 V2 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Bh622 V2 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Bh640 V2 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ch121 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ch140 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ch220 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ch221 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ch222 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ch240 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ch242 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Ch242 V3 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei E6000 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei E6000 Chassis | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r001c01spc100 |
| Running on/with | Platform Versions |
|---|---|
Huawei Gtsoftx3000 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c30spc300 |
| Running on/with | Platform Versions |
|---|---|
Huawei Oceanstor 18500 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c30spc300 |
| Running on/with | Platform Versions |
|---|---|
Huawei Oceanstor 18800 | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c30spc300 |
| Running on/with | Platform Versions |
|---|---|
Huawei Oceanstor 18800f | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Oceanstor Hvs85t | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Oceanstor Hvs88t | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Rh1288 V2 | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Rh1288a V2 | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Rh2265 V2 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Rh2268 V2 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Rh2285 V2 | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Rh2285h V2 | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Rh2288 V2 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Rh2288a V2 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Rh2288e V2 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Rh2288h V2 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Rh2485 V2 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Rh5885 V2 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r003c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Rh5885 V3 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version v500r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Smc2.0 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Seco Vsm | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Uma | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r002c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei X6000 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Version v100r002c20 |
| Running on/with | Platform Versions |
|---|---|
Huawei X8000 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version v200r003c10 |
| Running on/with | Platform Versions |
|---|---|
Huawei Elog | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version v300r001c00 |
| Running on/with | Platform Versions |
|---|---|
Huawei Espace Ecs | All versions |
References (29)
Source: secure@microsoft.com
ExploitThird Party AdvisoryVDB Entry
Source: secure@microsoft.com
ExploitThird Party AdvisoryVDB Entry
Source: secure@microsoft.com
ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/155389/Microsoft-Windows-7-x86-BlueKeep-RDP-Use-After-Free.html
Source: secure@microsoft.com
Third Party AdvisoryVDB Entry
Source: secure@microsoft.com
ExploitThird Party AdvisoryVDB Entry
Source: secure@microsoft.com
Third Party Advisory
Source: secure@microsoft.com
Third Party Advisory
Source: secure@microsoft.com
Third Party Advisory
Source: secure@microsoft.com
Third Party Advisory
Source: secure@microsoft.com
Third Party Advisory
Source: secure@microsoft.com
Third Party Advisory
Source: secure@microsoft.com
Third Party Advisory
Source: secure@microsoft.com
Third Party Advisory
Source: secure@microsoft.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/155389/Microsoft-Windows-7-x86-BlueKeep-RDP-Use-After-Free.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.