← Back

CVE-2019-1226

nvd nist
Published: Aug 14, 2019Modified: Feb 20, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: secure@microsoft.com (Secondary)

Description

A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would need to send a specially crafted request to the target systems Remote Desktop Service via RDP. The update addresses the vulnerability by correcting how Remote Desktop Services handles connection requests.

Affected (6)

3 products
Windows 10
Windows Server 2016
Windows Server 2019
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Version 1803
Version 1809
Version 1903
Microsoft
Version 1803
Version 1903
All versions

References (6)

Timeline

No history available yet.