You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2019-0708
About this tag
CVE-2019-0708, also known as BlueKeep, is a critical remote code execution vulnerability in Microsoft's Remote Desktop Services (RDS), formerly Terminal Services. It affects older Windows versions including Windows 7, Windows Server 2008 R2, Windows XP, and Windows Server 2003. The vulnerability is pre-authentication and requires no user interaction, making it wormable—similar to WannaCry. Microsoft released patches for out-of-support systems via the Windows Update Catalog. Discussions on WindowsForum cover the CISA alert, technical details, and guidance to prevent exploitation by updating RDS. Users are advised to apply patches immediately to protect against potential malware propagation.
Original release date: June 17, 2019
Summary
The Cybersecurity and Infrastructure Security Agency (CISA) is issuing this Activity Alert to provide information on a vulnerability, known as “BlueKeep,” that exists in the following Microsoft Windows Operating Systems (OSs), including both 32- and...
authentication
bluekeep
cisa
cve-2019-0708
cybersecurity
end of life
exploitation
malware
microsoft
mitigation
operating system
patch
patch management
rdp
remote access
security
tcp/ip
user rights
vulnerability
windows
Pretty significant vulnerability that Microsoft is patching even for out of support versions of Windows. For the out of support the update is available only through the Windows Update Catalog. Microsoft Update Catalog
TechNet Blog about the vulnerability and direct links to the patch download...
catalog
cve-2019-0708
exploit
microsoft
network
outdated
patch
rdp
remote desktop
risk
security
software
support
system
technet
update
vulnerability
windows
windows update
Today Microsoft released fixes for a critical Remote Code Execution vulnerability, CVE-2019-0708, in Remote Desktop Services – formerly known as Terminal Services – that affects some older versions of Windows. The Remote Desktop Protocol (RDP) itself is not vulnerable. This vulnerability is...
authentication
cve-2019-0708
emergency patch
exploit
extended security updates
legacy systems
malware
microsoft security
network level authentication
out-of-support
patch management
remote code execution
remote desktop
vulnerability
wannacry
windows 2003
windows 2008
windows 7
windows server
windows xp