CVE-2019-0708

Kritisch9.8Veröffentlicht am 16. Mai 2019

Eine Schwachstelle zur Remotecodeausführung besteht in Remote Desktop Services, früher bekannt als Terminal Services, wenn ein nicht authentifizierter Angreifer über RDP eine Verbindung zum Zielsystem herstellt und speziell gestaltete Anfragen sendet, auch bekannt als „Remote Desktop Services Remote Code Execution Vulnerability“.

Aktiv ausgenutzt

  • Seit dem 3. Nov. 2021 im CISA-Katalog ausgenutzter Schwachstellen
  • US-Bundesbehörden müssen sie bis zum 3. Mai 2022 beheben (BOD 22-01)
  • Erster Angriff 76 Tage nach der Veröffentlichung beobachtet
  • Durch Sensoren bestätigt, nicht nur durch Meldungen
  • In Ransomware-Kampagnen eingesetzt

Apply updates per vendor instructions.

Quelle: CISA KEV · 16. Sept. 2026 20. Jan. 2026 18. Nov. 2025 25. Aug. 2025 26. Juni 2025 25. Juni 2025

CVSS-Score9.8 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Schwachstellentyp (CWE)CWE-416, CWE-416
Herstellersiemens, microsoft

Betroffene Produkte

HerstellerProduktVersionen
microsoftwindows 7-
microsoftwindows server 2008-
siemensaxiom multix m firmware
siemensaxiom multix m-
siemensaxiom vertix md trauma firmware
siemensaxiom vertix md trauma-
siemensaxiom vertix solitaire m firmware
siemensaxiom vertix solitaire m-
siemensmobilett xp digital firmware
siemensmobilett xp digital-
siemensmultix pro acss p firmware
siemensmultix pro acss p-
siemensmultix pro p firmware
siemensmultix pro p-
siemensmultix pro firmware
siemensmultix pro-
siemensmultix pro acss firmware
siemensmultix pro acss-
siemensmultix pro navy firmware
siemensmultix pro navy-
siemensmultix swing firmware
siemensmultix swing-
siemensmultix top firmware
siemensmultix top-
siemensmultix top acss firmware

Verwandte Artikel

This product uses the NVD API but is not endorsed or certified by the NVD.

Die technische Beschreibung ist unsere Übersetzung des englischen NVD-Originaltexts.

CVE-Datenbank