cbcvebase.
CVE-2019-0708
published 2019-05-16

CVE-2019-0708: A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the…

PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
100.00%
100.0th percentile
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

Affected

67 ranges· showing 25
VendorProductVersion rangeFixed in
huaweiagile_controller-campus_firmware
huaweiagile_controller-campus_firmware
huaweibh620_v2_firmware
huaweibh621_v2_firmware
huaweibh622_v2_firmware
huaweibh640_v2_firmware
huaweich121_firmware
huaweich140_firmware
huaweich220_firmware
huaweich221_firmware
huaweich222_firmware
huaweich240_firmware
huaweich242_firmware
huaweich242_v3_firmware
huaweie6000_chassis_firmware
huaweie6000_firmware
huaweielog_firmware
huaweiespace_ecs_firmware
huaweigtsoftx3000_firmware
huaweigtsoftx3000_firmware
huaweigtsoftx3000_firmware
huaweioceanstor_18500_firmware
huaweioceanstor_18800_firmware
huaweioceanstor_18800f_firmware
huaweioceanstor_hvs85t_firmware

Detection & IOCsextracted from sources · hover to see the quote

hashE5D9C9C78ABB247C30E3E9BBD5103CD559FD54C9C616237DEC896DD42908449A
  • The 'Frenchy' custom AutoIT packer checks for 'vmtoolsd.exe' and 'vbox.exe' at runtime; presence of these process checks in an AutoIT-delivered sample is a behavioral indicator of this packer family.
  • The 'Frenchy' packer achieves persistence by creating a shortcut inside the user's startup directory and drops a VisualBasic script plus a copy of itself into an arbitrary folder under the user's profile directory.
  • The 'Frenchy' packer uses two UAC bypass techniques: event viewer UAC bypass for Windows 7/8 targets, and fodhelper for Windows 10 targets.
  • The 'Frenchy' packer uses process hollowing and injects into different legitimate Microsoft executables depending on the resource type embedded in the sample.
  • Fortinet detects the 'Frenchy' packer family (used to deliver Lokibot and other malware) under the signature name AutoIt/Injector.ELI!tr.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
vendor_msrc9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.