cbcvebase.
CVE-2019-1182
published 2019-08-14

CVE-2019-1182: A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to…

PriorityP269critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
12.93%
95.9th percentile
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would need to send a specially crafted request to the target systems Remote Desktop Service via RDP. The update addresses the vulnerability by correcting how Remote Desktop Services handles connection requests.

Affected

43 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftmicrosoft_remote_desktop_for_android< publicationpublication
microsoftmicrosoft_remote_desktop_for_ios>= 1.0.0 < publicationpublication
microsoftmicrosoft_remote_desktop_for_mac>= 1.0.0 < publicationpublication
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_version_1507>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1607>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1703>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1709>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1709_for_32-bit_systems>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1803>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1809>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1903_for_32-bit_systems>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1903_for_arm64-based_systems>= 10.0.0 < publicationpublication
microsoftwindows_10_version_1903_for_x64-based_systems>= 10.0.0 < publicationpublication
microsoftwindows_8.1>= 6.3.0 < publicationpublication
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.0 < publicationpublication
microsoftwindows_server_2012_r2>= 6.3.0 < publicationpublication
microsoftwindows_server_2016
microsoftwindows_server_2016

Detection & IOCsextracted from sources · hover to see the quote

portTCP 3389
snort
SID 51369 — OS-WINDOWS Microsoft Windows RDP DecompressUnchopper integer overflow attempt
  • CVE-2019-1182 (DejaBlue) exploits arrive as unauthenticated, pre-auth RDP requests on TCP/3389; monitor for anomalous RDP connection attempts that do not complete NLA authentication.
  • RDP traffic must be decrypted (via static RSA key / known-key SSL decryption) before the DejaBlue Snort rule (SID 51369) can fire; configure Firepower or equivalent inline IPS with RDP TLS decryption using the server's exported certificate and private key.
  • On Windows 7 SP1 / Server 2008 R2 SP1, the vulnerability is only present if RDP 8.0 or RDP 8.1 is installed; scope detection and patching efforts accordingly.
  • ·Snort SID 51369 only blocks exploitation when RDP TLS decryption is configured on the inline Firepower device; without decryption the rule cannot inspect the payload.
  • ·Enabling Network Level Authentication (NLA) is only a partial mitigation — it forces authentication before the exploitable code path is reached but does not fully remediate the vulnerability.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_msrc9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.