RULE(RULE ID:712819)

Rule General Information
Release Date: 2019-05-21
Rule Name: Inbound RDP Exploitation Vulnerability (CVE-2019-0708)
Severity:
CVE ID:
Rule Protection Details
Description: A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
Impact: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: SecurityFocusBID:108273
https://nvd.nist.gov/vuln/detail/CVE-2019-0708
http://www.microsoft.com/windows/default.mspx
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://portal.msrc.microsoft.com/zh-CN/security-guidance/advisory/CVE-2019-0708