PT-2019-2094 · Microsoft+1 · Remote Desktop Services+2
CVE-2019-0708
·
Published
2019-05-14
·
Updated
2026-08-21
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Windows 7 (affected versions not specified)
Windows Server 2008 R2 (affected versions not specified)
Description
A remote code execution issue exists in Remote Desktop Services (formerly known as Terminal Services) due to a kernel Use-After-Free (UAF) error in the Remote Desktop Protocol (RDP). An unauthenticated attacker can exploit this by connecting to the target system via RDP and sending specially crafted requests. This pre-authentication flaw requires no user interaction and allows the attacker to execute arbitrary code on the target system. Successful exploitation could enable the installation of programs, the ability to view, modify, or delete data, and the creation of new accounts with full user privileges.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Huawei Vrp
Remote Desktop Services
Windows