Back

CVE-2019-0708

CRITICAL CISA KEV

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

Published: May 16, 2019 Modified: Jun 17, 2026
CWE-416 CWE-416

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (75)

Vendor Product Version
microsoft windows_7 -
microsoft windows_server_2008 -
microsoft windows_server_2008 r2
siemens axiom_multix_m_firmware *
siemens axiom_vertix_md_trauma_firmware *
siemens axiom_vertix_solitaire_m_firmware *
siemens mobilett_xp_digital_firmware *
siemens multix_pro_acss_p_firmware *
siemens multix_pro_p_firmware *
siemens multix_pro_firmware *
siemens multix_pro_acss_firmware *
siemens multix_pro_navy_firmware *
siemens multix_swing_firmware *
siemens multix_top_firmware *
siemens multix_top_acss_firmware *
siemens multix_top_p_firmware *
siemens multix_top_acss_p_firmware *
siemens vertix_solitaire_firmware *
siemens atellica_solution_firmware *
siemens aptio_firmware *

…and 55 more

GitHub Security Advisory GHSA-fq64-gmq7-jjvg

A remote code execution vulnerability exists in Remote Desktop Services formerly known as...

References (29)

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 100.00%

Top 0% most likely to be exploited

Threat Score 99.2 / 100

CISA Known Exploited

Date Added: 2021-11-03
Due Date: 2022-05-03
Required Action:

Apply updates per vendor instructions.

Used in Ransomware Campaigns

Data Sources

NVD CISA KEV EPSS GitHub