PT-2019-2094 · Microsoft+1 · Remote Desktop Services+2

CVE-2019-0708

·

Published

2019-05-14

·

Updated

2026-08-21

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows 7 (affected versions not specified) Windows Server 2008 R2 (affected versions not specified)
Description A remote code execution issue exists in Remote Desktop Services (formerly known as Terminal Services) due to a kernel Use-After-Free (UAF) error in the Remote Desktop Protocol (RDP). An unauthenticated attacker can exploit this by connecting to the target system via RDP and sending specially crafted requests. This pre-authentication flaw requires no user interaction and allows the attacker to execute arbitrary code on the target system. Successful exploitation could enable the installation of programs, the ability to view, modify, or delete data, and the creation of new accounts with full user privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01846
CVE-2019-0708
MICROSOFTRDPCVE_2019_0708

Affected Products

Huawei Vrp
Remote Desktop Services
Windows