CVE-2019-1181 Details
Description
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would need to send a specially crafted request to the target systems Remote Desktop Service via RDP. The update addresses the vulnerability by correcting how Remote Desktop Services handles connection requests.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 19, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft windows 10 | 1607 1703 1709 1803 1809 1903 |
CPE
Remediation
| |
| microsoft windows 7 | All versions |
CPE
Remediation
| |
| microsoft windows 8.1 | All versions |
CPE
Remediation
| |
| microsoft windows rt 8.1 | All versions |
CPE
Remediation
| |
| microsoft windows server 2008 | All versions |
CPE
Remediation
| |
| microsoft windows server 2012 | r2 |
CPE
Remediation
| |
| microsoft windows server 2016 | 1803 1903 |
CPE
Remediation
| |
| microsoft windows server 2019 | All versions |
CPE
Remediation
| |
Change History
24 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 20, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 29, 2024 | CVE Modified | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Aug 24, 2020 | CWE Remap | [email protected] |
| Feb 10, 2020 | CVE Modified | [email protected] |
| Oct 10, 2019 | CVE Modified | [email protected] |
| Oct 10, 2019 | CVE Modified | [email protected] |
| Oct 10, 2019 | CVE Modified | [email protected] |
| Oct 10, 2019 | CVE Modified | [email protected] |
| Oct 10, 2019 | CVE Modified | [email protected] |
| Oct 10, 2019 | CVE Modified | [email protected] |
| Oct 10, 2019 | CVE Modified | [email protected] |
| Oct 10, 2019 | CVE Modified | [email protected] |
| Oct 10, 2019 | CVE Modified | [email protected] |
| Oct 10, 2019 | CVE Modified | [email protected] |
| Oct 10, 2019 | CVE Modified | [email protected] |
| Oct 10, 2019 | CVE Modified | [email protected] |
| Oct 9, 2019 | CVE Modified | [email protected] |
| Sep 10, 2019 | CVE Modified | [email protected] |
| Aug 19, 2019 | Initial Analysis | [email protected] |
| Aug 19, 2019 | CVE Modified | [email protected] |