Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.108611
Category:Windows : Microsoft Bulletins
Title:Microsoft Windows Remote Desktop Services RCE Vulnerability (CVE-2019-0708, BlueKeep) - Active Check
Summary:Microsoft Windows Remote Desktop Services is prone to a remote; code execution (RCE) vulnerability dubbed 'BlueKeep'.
Description:Summary:
Microsoft Windows Remote Desktop Services is prone to a remote
code execution (RCE) vulnerability dubbed 'BlueKeep'.

Vulnerability Insight:
A remote code execution vulnerability exists in Remote Desktop
Services when an unauthenticated attacker connects to the target system using RDP and sends
specially crafted requests. This vulnerability is pre-authentication and requires no user
interaction.

For an in-depth analysis and further technical insights and details please see the references.

Vulnerability Impact:
Successful exploitation would allow an attacker to execute
arbitrary code on the target system. An attacker could then install programs, view, change, or
delete data, or create new accounts with full user rights.

Affected Software/OS:
- Microsoft Windows 7

- Microsoft Windows Server 2008 R2

- Microsoft Windows Server 2008

- Microsoft Windows Server 2003 R2

- Microsoft Windows Server 2003

- Microsoft Windows Vista and Microsoft Windows XP (including Embedded)

Solution:
The vendor has released updates. Please see the references for
more information.

As a workaround enable Network Level Authentication (NLA) on systems running supported editions of
Windows 7, Windows Server 2008, and Windows Server 2008 R2.

NOTE: After enabling NLA affected systems are still vulnerable to Remote Code Execution (RCE)
exploitation if the attacker has valid credentials that can be used to successfully
authenticate.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2019-0708
http://packetstormsecurity.com/files/153133/Microsoft-Windows-Remote-Desktop-BlueKeep-Denial-Of-Service.html
http://packetstormsecurity.com/files/153627/Microsoft-Windows-RDP-BlueKeep-Denial-Of-Service.html
http://packetstormsecurity.com/files/154579/BlueKeep-RDP-Remote-Windows-Kernel-Use-After-Free.html
http://packetstormsecurity.com/files/155389/Microsoft-Windows-7-x86-BlueKeep-RDP-Use-After-Free.html
http://packetstormsecurity.com/files/162960/Microsoft-RDP-Remote-Code-Execution.html
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708
CopyrightCopyright (C) 2019 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.