CVE-2019-1182

A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services? Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1181, CVE-2019-1222, CVE-2019-1226.

Published : 2019-08-14 21:15 Updated : 2019-10-10 12:10

10.0
CVSS Score More info
Score 10.0 / 10
10.0
Vendor Product Version URI
Microsoft Windows 10 - cpe:/o:microsoft:windows_10:-
Microsoft Windows 10 1607 cpe:/o:microsoft:windows_10:1607
Microsoft Windows 10 1703 cpe:/o:microsoft:windows_10:1703
Microsoft Windows 10 1709 cpe:/o:microsoft:windows_10:1709
Microsoft Windows 10 1803 cpe:/o:microsoft:windows_10:1803
Microsoft Windows 10 1809 cpe:/o:microsoft:windows_10:1809
Microsoft Windows 10 1903 cpe:/o:microsoft:windows_10:1903
Microsoft Windows 7 - cpe:/o:microsoft:windows_7:-:sp1
Microsoft Windows 8.1 - cpe:/o:microsoft:windows_8.1:-
Microsoft Windows Rt 8.1 - cpe:/o:microsoft:windows_rt_8.1:-
Microsoft Windows Server 2008 - cpe:/o:microsoft:windows_server_2008:-:sp2
Microsoft Windows Server 2012 - cpe:/o:microsoft:windows_server_2012:-
Microsoft Windows Server 2012 r2 cpe:/o:microsoft:windows_server_2012:r2
Microsoft Windows Server 2016 - cpe:/o:microsoft:windows_server_2016:-
Microsoft Windows Server 2016 1803 cpe:/o:microsoft:windows_server_2016:1803
Microsoft Windows Server 2016 1903 cpe:/o:microsoft:windows_server_2016:1903
Microsoft Windows Server 2019 - cpe:/o:microsoft:windows_server_2019:-
  1. Microsoft (8) Search CVE
    1. Windows Rt 8.1 (1) Search CVE
      1. -
    2. Windows 7 (1) Search CVE
      1. -
    3. Windows 10 (7) Search CVE
      1. -
      2. 1607
      3. 1703
      4. 1709
      5. 1803
      6. 1809
      7. 1903
    4. Windows 8.1 (1) Search CVE
      1. -
    5. Windows Server 2008 (1) Search CVE
      1. -
    6. Windows Server 2012 (2) Search CVE
      1. -
      2. R2
    7. Windows Server 2016 (3) Search CVE
      1. -
      2. 1803
      3. 1903
    8. Windows Server 2019 (1) Search CVE
      1. -

CWE

ID Name Description Links
CWE-284 Improper Access Control The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor. CVE

History of changes

Date Event
2019-09-10 13:15
2019-08-19 18:09
2019-08-19 11:15
2019-08-14 21:15

New CVE