HomeOur Team

Remote Desktop Services - Vulnerability

By Tom Grant
Published in OS
April 09, 2020
1 min read

CVE-2019-0708 - Security Vulnerability

A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

To exploit this vulnerability, an attacker would need to send a specially crafted request to the target systems Remote Desktop Service via RDP.

The update addresses the vulnerability by correcting how Remote Desktop Services handles connection requests.

source: portal.msrc.microsoft.com


Previous Article
Popular Convert Plus Plugin Vulnerability Exploit
Tom Grant

Tom Grant

Product Designer

Related Posts

Critical RCE bug found in VLC Media Player
March 25, 2020
1 min
© 2022, All Rights Reserved.

Quick Links

Our TeamContact Us

Legal Stuff

Social Media