CVE-2019-1182
published 2019-08-14CVE-2019-1182: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to…
PriorityP269critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
12.93%
95.9th percentile
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would need to send a specially crafted request to the target systems Remote Desktop Service via RDP.
The update addresses the vulnerability by correcting how Remote Desktop Services handles connection requests.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_remote_desktop_for_android | < publication | publication |
| microsoft | microsoft_remote_desktop_for_ios | >= 1.0.0 < publication | publication |
| microsoft | microsoft_remote_desktop_for_mac | >= 1.0.0 < publication | publication |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1507 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1607 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1703 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1709 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1709_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1803 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_arm64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_x64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_8.1 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.0 < publication | publication |
| microsoft | windows_server_2012_r2 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2016 | — | — |
| microsoft | windows_server_2016 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
snort↗
SID 51369 — OS-WINDOWS Microsoft Windows RDP DecompressUnchopper integer overflow attempt
- →CVE-2019-1182 (DejaBlue) exploits arrive as unauthenticated, pre-auth RDP requests on TCP/3389; monitor for anomalous RDP connection attempts that do not complete NLA authentication. ↗
- →RDP traffic must be decrypted (via static RSA key / known-key SSL decryption) before the DejaBlue Snort rule (SID 51369) can fire; configure Firepower or equivalent inline IPS with RDP TLS decryption using the server's exported certificate and private key. ↗
- →On Windows 7 SP1 / Server 2008 R2 SP1, the vulnerability is only present if RDP 8.0 or RDP 8.1 is installed; scope detection and patching efforts accordingly. ↗
- ·Snort SID 51369 only blocks exploitation when RDP TLS decryption is configured on the inline Firepower device; without decryption the rule cannot inspect the payload. ↗
- ·Enabling Network Level Authentication (NLA) is only a partial mitigation — it forces authentication before the exploitable code path is reached but does not fully remediate the vulnerability. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qcg4-w26w-fjv8: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker conne
ghsa_unreviewed·2022-05-24·CVSS 9.8
CVE-2019-1226 [CRITICAL] GHSA-qcg4-w26w-fjv8: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker conne
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services? Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1181, CVE-2019-1182, CVE-2019-1222.
GHSA
GHSA-vw3c-3fmq-qpgq: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker conne
ghsa_unreviewed·2022-05-24·CVSS 9.8
CVE-2019-1182 [CRITICAL] GHSA-vw3c-3fmq-qpgq: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker conne
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services? Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1181, CVE-2019-1222, CVE-2019-1226.
GHSA
GHSA-w8p3-q4q6-xq79: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker conne
ghsa_unreviewed·2022-05-24·CVSS 9.8
CVE-2019-1181 [CRITICAL] GHSA-w8p3-q4q6-xq79: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker conne
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services? Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1182, CVE-2019-1222, CVE-2019-1226.
GHSA
GHSA-qvf2-39c6-g8rr: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker conne
ghsa_unreviewed·2022-05-24·CVSS 9.8
CVE-2019-1222 [CRITICAL] GHSA-qvf2-39c6-g8rr: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker conne
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services? Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1181, CVE-2019-1182, CVE-2019-1226.
Microsoft
Remote Desktop Services Remote Code Execution Vulnerability
vendor_msrc·2019-08-13·CVSS 9.8
CVE-2019-1182 [CRITICAL] Remote Desktop Services Remote Code Execution Vulnerability
Remote Desktop Services Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would need to send a specially crafted request to the target systems Remote Desktop Service via RDP.
The update addresses the vulnerability by correcting how R
No detection rules found.
No public exploits indexed.
Tenable
Healthcare Security: Ransomware Plays a Prominent Role in COVID-19 Era Breaches
blogs_tenable·2021-03-10
Healthcare Security: Ransomware Plays a Prominent Role in COVID-19 Era Breaches
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Microsoft’s January 2020 Patch Tuesday Kicks Off the New Year with 49 New CVEs
blogs_tenable·2020-01-14
Microsoft’s January 2020 Patch Tuesday Kicks Off the New Year with 49 New CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Objects in Mirror Are Closer Than They Appear: Reflecting on the Cybersecurity Threats from 2019
blogs_tenable·2019-12-16
Objects in Mirror Are Closer Than They Appear: Reflecting on the Cybersecurity Threats from 2019
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
The latest on BlueKeep and DejaBlue vulnerabilities — Using Firepower to defend against encrypted DejaBlue
blogs_talos·2019-11-04·CVSS 9.8
CVE-2019-0708 [CRITICAL] The latest on BlueKeep and DejaBlue vulnerabilities — Using Firepower to defend against encrypted DejaBlue
Update (11/04/2019):
There have been several public reports of active exploitation of CVE-2019-0708, commonly referred to as “BlueKeep.” Preliminary reportsindicate that the vulnerability is being exploited by adversaries who are leveraging access to compromised systems to install cryptocurrency mining malware. At this time, there has been no evidence to suggest that the exploitation is due to the emergence of a new worm, and it is likely being done as part of a mass exploitation campaign, similar to what we have seen in previous instances of mass exploitation campaigns. Existing coverage for BlueKeep continues to be an effective way to mitigate possible exploitation attempts. For additional information related to protecting against attacks leveraging BlueKeep, please refer to the blog pos
Krebs
Patch Tuesday, August 2019 Edition
blogs_krebs·2019-08-27·CVSS 9.8
[CRITICAL] Patch Tuesday, August 2019 Edition
Most Microsoft Windows (ab)users probably welcome the monthly ritual of applying security updates about as much as they look forward to going to the dentist: It always seems like you were there just yesterday, and you never quite know how it’s all going to turn out. Fortunately, this month’s patch batch from Redmond is mercifully light, at least compared to last month.
Although there don’t appear to be any zero-day vulnerabilities fixed this month — i.e. those that get exploited by cybercriminals before an official patch is available — there are several issues that merit attention.
Chief among those are patches to address four moderately terrifying flaws in Microsoft’s Remote Desktop Service, a feature which allows users to remotely access and administer a Windows computer as if they wer
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
# August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro
Aug 14, 2019
Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the time of release, a few of the bu
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Exploits & Vulnerabilities
## August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro Aug 14, 2019 Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the time
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Exploits & Vulnerabilities
# August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro
2019/08/14
Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the time o
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Ausnutzung von Schwachstellen
## August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro Aug 14, 2019 Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the t
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Exploits y vulnerabilidades
## August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro Aug 14, 2019 Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the tim
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
## August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro Aug 14, 2019 Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the time of release, a few of the bu
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Exploits & Vulnerabilities
## August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro 2019/08/14 Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the time o
Trendmicro
August Patch Tuesday: Fixes for ‘Wormable’ Flaws
blogs_trendmicro·2019-08-14·CVSS 9.8
[CRITICAL] August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Sfruttamento vulnerabilità
## August Patch Tuesday: Fixes for ‘Wormable’ Flaws
Among the bugs addressed the August Patch Tuesday are notable “wormable” ones, namely remote code execution (RCE) vulnerabilities in the Remote Desktop Services.
By: Trend Micro Aug 14, 2019 Read time: ( words)
Save to Folio
Microsoft released updates to patch 93 CVEs, along with two advisories, in this month’s Patch Tuesday. The bulletin patches issues in Azure DevOps Server, Internet Explorer, Microsoft Office, Microsoft Windows, Visual Studio, to name a few. The patches address 29 vulnerabilities rated Critical and 64 that were rated Important. A total of 21 CVEs were disclosed through the Zero Day Initiative (ZDI) program.
While none of the vulnerabilities were listed as under active attack at the time
Qualys
August 2019 Patch Tuesday – 93 Vulns, 29 Critical, 7 Remote Desktop Vulns, Hyper-V, DHCP, Adobe vulns
blogs_qualys·2019-08-13·CVSS 9.8
[CRITICAL] August 2019 Patch Tuesday – 93 Vulns, 29 Critical, 7 Remote Desktop Vulns, Hyper-V, DHCP, Adobe vulns
Update Aug 13, 2019 : Detect and Patch Windows Remote Desktop Vulnerabilities
This month’s Microsoft Patch Tuesday addresses 93 vulnerabilities with 29 of them labeled as Critical. Of the 29 Critical vulns, 10 are for scripting engines and browsers, 6 for Windows Graphics/Font Library, and 4 are for Office apps. In addition, Microsoft has patched 4 (!) Critical RCEs in Remote Desktop (plus 3 Important), 2 for Hyper-V, 2 in DHCP Client/Server, and one for LNK files. Adobe has also released a large number of patches covering multiple products.
## Workstation Patches
Scripting Engine, Browser, Office, Graphics/Font, and LNK patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user
Talos
Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
blogs_talos·2019-08-13·CVSS 9.1
[CRITICAL] Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
Microsoft released its monthly security update today, disclosing a variety of vulnerabilities in several of its products. The latest Patch Tuesday covers 97 vulnerabilities, 31 of which are rated “critical," 65 that are considered "important" and one "moderate."
This month’s security update covers security issues in a variety of Microsoft services and software, including certain graphics components, Outlook and the Chakra Scripting Engine. For more on our coverage of these bugs, check out our Snort advisories here, covering all of the new rules we have for this release.
### Critical vulnerabilities Microsoft disclosed 31 critical vulnerabilities this month, three of which we will highlight below.
CVE-2019-1181 and CVE-2019-1182 are both remote code execution vulnerabilities in Remote De
Tenable
Tenable Roundup for Microsoft’s August 2019 Patch Tuesday: DejaBlue
blogs_tenable·2019-08-13
Tenable Roundup for Microsoft’s August 2019 Patch Tuesday: DejaBlue
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Krebs
Patch Tuesday, August 2019 Edition
blogs_krebs·2019-08-13·CVSS 9.8
[CRITICAL] Patch Tuesday, August 2019 Edition
Most Microsoft Windows (ab)users probably welcome the monthly ritual of applying security updates about as much as they look forward to going to the dentist: It always seems like you were there just yesterday, and you never quite know how it’s all going to turn out. Fortunately, this month’s patch batch from Redmond is mercifully light, at least compared to last month.
Okay, maybe a trip to the dentist’s office is still preferable. In any case, today is the second Tuesday of the month, which means it’s once again Patch Tuesday (or — depending on your setup and when you’re reading this post — Reboot Wednesday). Microsoft today released patches to fix some 93 vulnerabilities in Windows and related software, 35 of which affect various Server versions of Windows, and another 70 that apply to
Qualys
Windows Remote Desktop Vulnerabilities (Seven Monkeys) – How to Detect and Patch
blogs_qualys·2019-08-13·CVSS 9.8
[CRITICAL] Windows Remote Desktop Vulnerabilities (Seven Monkeys) – How to Detect and Patch
## Table of Contents
Authenticated check:
Remediating with Qualys Patch Management:
Patch Links:
Mitigation:
Workarounds:
Resources:
In the August 2019 Patch Tuesday release, Microsoft disclosed 7 RDP Vulnerabilities, out of which 4 are labeled as critical and 3 as important. All the critical vulnerabilities exist in Remote Desktop Services – formerly known as Terminal Services – and do not require authentication or user interaction. To exploit the vulnerabilities, an attacker would need to send a specially crafted request to the target systems Remote Desktop Service via RDP.
The cyber industry has named them as Seven Monkeys pertaining to seven CVEs released. Microsoft has released patches for these vulnerabilities and at least two of these (CVE-2019-1181 & CVE-2019-1182) can be c
Talos
Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
blogs_talos·2019-08-13·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
## Microsoft Patch Tuesday — Aug. 2019: Vulnerability disclosures and Snort coverage
Microsoft released its monthly security update today, disclosing a variety of vulnerabilities in several of its products. The latest Patch Tuesday covers 97 vulnerabilities, 31 of which are rated “critical," 65 that are considered "important" and one "moderate."
This month’s security update covers security issues in a variety of Microsoft services and software, including certain graphics components, Outlook and the Chakra Scripting Engine. For more on our coverage of these bugs, check out our Snort advisories here , covering all of the new rules we have for this release.
## Critical vulnerabilities Microsoft disclosed 31 critical vulnerabilities this month, three of which we will highlight below.
CVE-2
Qualys
August 2019 Patch Tuesday - 93 Vulns, 29 Critical, 7 Remote Desktop Vulns, Hyper-V, DHCP, Adobe vulns | Qualys
blogs_qualys·2019-08-13·CVSS 9.8
[CRITICAL] August 2019 Patch Tuesday - 93 Vulns, 29 Critical, 7 Remote Desktop Vulns, Hyper-V, DHCP, Adobe vulns | Qualys
Update Aug 13, 2019: Detect and Patch Windows Remote Desktop Vulnerabilities
This month’s Microsoft Patch Tuesday addresses 93 vulnerabilities with 29 of them labeled as Critical. Of the 29 Critical vulns, 10 are for scripting engines and browsers, 6 for Windows Graphics/Font Library, and 4 are for Office apps. In addition, Microsoft has patched 4 (!) Critical RCEs in Remote Desktop (plus 3 Important), 2 for Hyper-V, 2 in DHCP Client/Server, and one for LNK files. Adobe has also released a large number of patches covering multiple products.
### Workstation Patches
Scripting Engine, Browser, Office, Graphics/Font, and LNK patches should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user
Qualys
Windows Remote Desktop Vulnerabilities (Seven Monkeys) – How to Detect and Patch | Qualys
blogs_qualys·2019-08-13·CVSS 9.8
[CRITICAL] Windows Remote Desktop Vulnerabilities (Seven Monkeys) – How to Detect and Patch | Qualys
#### Table of Contents
- Authenticated check:
- Remediating with Qualys Patch Management:
- Patch Links:
- Mitigation:
- Workarounds:
- Resources:
In the August 2019 Patch Tuesday release, Microsoft disclosed 7 RDP Vulnerabilities, out of which 4 are labeled as critical and 3 as important. All the critical vulnerabilities exist in Remote Desktop Services – formerly known as Terminal Services – and do not require authentication or user interaction. To exploit the vulnerabilities, an attacker would need to send a specially crafted request to the target systems Remote Desktop Service via RDP.
The cyber industry has named them as Seven Monkeys pertaining to seven CVEs released. Microsoft has released patches for these vulnerabilities and at least two of these (CVE-2019-1181 & CVE-2019-1182)
Zscaler
Zscaler found Multiple Security Vulnerabilities | 08-14-2019
blogs_zscaler·CVSS 4.2
[MEDIUM] Zscaler found Multiple Security Vulnerabilities | 08-14-2019
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190819-01-windows-enhttps://cert-portal.siemens.com/productcert/pdf/ssa-187667.pdfhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1182http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190819-01-windows-enhttps://cert-portal.siemens.com/productcert/pdf/ssa-187667.pdfhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-1182
2019-08-14
Published