CVE detail
CVE-2019-1182
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would need to send a specially crafted request to the target systems Remote Desktop Service via RDP. The update addresses the vulnerability by correcting how Remote Desktop Services handles connection requests.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 9.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- Defending against Windows RDP attacksHelp Net Security
In 2020, attacks against Windows Remote Desktop Protocol (RDP) grew by 768%, according to ESET. But this shouldn’t come as a surprise, given the massive increase in the number of people working remotely during the pandemic. With enterprises resorting to making RDP services publicly available, hackers have taken notice. Some DDoS attacks are leveraging RDP servers to amplify their effect, and malware like Trickbot is employing scanners to identify vulnerable open RDP ports. When it … More →
newswww.helpnetsecurity.comMay 10, 2021, 4:00 AM For the September 2019 Patch Tuesday, Microsoft delivered fixes for 80 CVE-numbered security issues (including to actively exploited zero-days), Adobe fixed flaws in Flash Player and Application Manager, and Intel offered solutions and mitigations for two security holes, one of which could allow a side-channel attack aimed at acquiring sensitive data (e.g., keystrokes in a SSH session). Microsoft’s patches Let’s start with the zero-days exploited in the wild. CVE-2019-1214 is an elevation of privilege vulnerability … More →
newswww.helpnetsecurity.comSep 11, 2019, 9:08 AM- How to avoid using RDP on WindowsCSO Online
The recent discovery of several security vulnerabilities targeting Remote Desktop Protocol (RDP) has led to warnings that we should immediately patch Windows. CVE-2019-0708 (BlueKeep), CVE-2019-1181 (BlueKeep II), and CVE-2019-1182 (BlueKeep III) all rely on the fact that many admins still set up servers and leave them open to remote access over the internet. Reviewing what […]
newswww.csoonline.comAug 21, 2019, 10:00 AM Microsoft has identified and patched several vulnerabilities in the Windows Remote Desktop Services (RDS) component — formerly known as Terminal Services — which is widely used in corporate environments to remotely manage Windows machines. Some of the vulnerabilities can be exploited without authentication to achieve remote code execution and full system compromise, making them highly […]
newswww.csoonline.comAug 14, 2019, 11:55 PMMicrosoft’s latest security updates patch more wormable vulnerabilities related to Remote Desktop Services (RDS) and the company has published a blog post to warn users about the risk they pose.
newswww.securityweek.comAug 14, 2019, 1:33 PMIt’s that time of the month again: Microsoft, Adobe and Intel have pushed out fixes for a bucketload of security issues in their various software. Microsoft’s security updates should take precedence, though, as they fix 29 critical vulnerabilities, including four in Remote Desktop Services, two of which – Microsoft warns – are wormable, just like BlueKeep before them. Microsoft patches Microsoft has plugged 93 CVEs and has released two advisories – one recommends a new … More →
newswww.helpnetsecurity.comAug 14, 2019, 10:54 AM- Microsoft Patch Tuesday for August 2019 patch 93 bugs, including 2 dangerous wormable issuesSecurity Affairs
Microsoft Patches Over 90 Vulnerabilities With August 2019 Updates Microsoft Patch Tuesday security updates for August 2019 address more than 90 flaws, including two new ‘wormable‘ issues in Windows Remote Desktop Services. Microsoft Patch Tuesday security updates for August 2019 fix 93 vulnerabilities, including two new ‘wormable‘ issues in Windows Remote Desktop Services. The list […]
newssecurityaffairs.comAug 14, 2019, 7:05 AM Microsoft’s August 2019 Patch Tuesday updates fix more than 90 vulnerabilities, but none of them have been exploited in attacks or disclosed publicly before the patches were released.
newswww.securityweek.comAug 13, 2019, 7:03 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-21776CVSS 5.5 · Medium
Windows Kernel Information Disclosure Vulnerability
- CVE-2023-21765CVSS 7.8 · High
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2023-21760CVSS 7.1 · High
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2023-21757CVSS 7.5 · High
Windows Layer 2 Tunneling Protocol (L2TP) Denial of Service Vulnerability
- CVE-2023-21746CVSS 7.8 · High
Windows NTLM Elevation of Privilege Vulnerability
1 mention - CVE-2022-44697CVSS 7.8 · High
Windows Graphics Component Elevation of Privilege Vulnerability