← לוח פגיעויות

CVE-2019-0708

קריטית 9.8 מנוצלת בשטח (KEV) בשימוש בכופרה

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Microsoft Remote Desktop Services Remote Code Execution Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
100% (אחוזון 100) נכון ל-30/7/2026
CWE
CWE-416

מוצרים מושפעים

microsoft: windows 7; microsoft: windows server 2008; siemens: axiom multix m firmware; siemens: axiom multix m; siemens: axiom vertix md trauma firmware; siemens: axiom vertix md trauma; siemens: axiom vertix solitaire m firmware; siemens: axiom vertix solitaire m; siemens: mobilett xp digital firmware; siemens: mobilett xp digital; siemens: multix pro acss p firmware; siemens: multix pro acss p; siemens: multix pro p firmware; siemens: multix pro p; siemens: multix pro firmware

קישורים