cbcvebase.
CVE-2019-1181
published 2019-08-14

CVE-2019-1181: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to…

PriorityP278critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
75.19%
99.5th percentile
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would need to send a specially crafted request to the target systems Remote Desktop Service via RDP. The update addresses the vulnerability by correcting how Remote Desktop Services handles connection requests.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftmicrosoft_remote_desktop_for_android< publicationpublication
microsoftmicrosoft_remote_desktop_for_ios>= 1.0.0 < publicationpublication
microsoftmicrosoft_remote_desktop_for_mac>= 1.0.0 < publicationpublication
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_version_1507>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1607>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1703>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1709>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1709_for_32-bit_systems>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1803>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1809>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1903_for_32-bit_systems>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1903_for_arm64-based_systems>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1903_for_x64-based_systems>= 10.0.0 < publicationpublication
microsoftwindows_8.1>= 6.3.0 < publicationpublication
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.0 < publicationpublication
microsoftwindows_server_2012_r2>= 6.3.0 < publicationpublication
microsoftwindows_server_2016
microsoftwindows_server_2016

Detection & IOCsextracted from sources · hover to see the quote

portTCP 3389
snort
SID 51369 — OS-WINDOWS Microsoft Windows RDP DecompressUnchopper integer overflow attempt
snort
51369
  • CVE-2019-1181 (DejaBlue) is a pre-authentication, no-user-interaction RCE over RDP; monitor for unauthenticated specially crafted RDP connection requests to TCP/3389.
  • RDP traffic is TLS-encrypted; effective detection of DejaBlue exploitation requires RDP/TLS decryption (static key decryption) before applying IPS rules.
  • For Cisco Firepower, configure the SSL policy to decrypt RDP on TCP 3389 using the server's static RSA key, then enable Snort SID 51369 in Drop-and-Generate mode.
  • Windows 7 SP1 / Server 2008 R2 SP1 are only affected if RDP 8.0 or RDP 8.1 is installed; scope detection/patching accordingly.
  • ·Enabling Network Level Authentication (NLA) forces attackers to authenticate before reaching the vulnerable code path, providing partial mitigation when patching is not immediately possible.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.