CVE-2019-1453Cross-site Scripting in Microsoft Windows

CWE-79Cross-site Scripting20 documents9 sources
Severity
7.5HIGHNVD
EPSS
10.0%
top 6.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 10
Latest updateMay 24

Description

A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability'.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-3w89-xp68-5ffh: A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially2022-05-24
CVEList
CVE-2019-1453: A denial of service vulnerability exists in Remote Desktop Protocol (RDP) when an attacker connects to the target system using RDP and sends specially2019-12-10

📋Vendor Advisories

2
Microsoft
Windows Remote Desktop Protocol (RDP) Denial of Service Vulnerability2019-12-10
Red Hat
jenkins: stored cross-site scripting in update center web pages (SECURITY-1453)2019-08-28

🕵️Threat Intelligence

11
Trendmicro
December Patch Tuesday: Fixes for components, RDP2019-12-11
Trendmicro
December Patch Tuesday: Fixes for components, RDP2019-12-11
Trendmicro
December Patch Tuesday: Fixes for components, RDP2019-12-11
Trendmicro
December Patch Tuesday: Fixes for components, RDP2019-12-11
Trendmicro
December Patch Tuesday: Fixes for components, RDP2019-12-11

💬Community

2
Bugzilla
CVE-2019-10383 jenkins: stored cross-site scripting in update center web pages (SECURITY-1453)2019-08-30
Bugzilla
CVE-2019-7398 ImageMagick: Memory leak in the WriteDIBImage function in coders/dib.c2019-02-05
CVE-2019-1453 — Cross-site Scripting in Microsoft | cvebase