CVE-2019-1182 is a critical remote code execution vulnerability affecting Microsoft Windows operating systems, including Windows 7, 8.1, 10, and various Windows Server versions. An unauthenticated attacker can exploit this pre-authentication flaw by sending specially crafted RDP requests, requiring no user interaction. Successful exploitation grants the attacker arbitrary code execution, allowing them to install programs, manipulate data, or create new accounts with full user rights. While not listed in KEV or having public Metasploit/Nuclei modules, it garnered significant community discussion and media coverage, indicating high awareness. The vulnerability's high CVSS score of 9.8 and FAUCET Risk Score of 97/100 underscore its severe potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:-:*:*:*:*:*:*:* | ||
1607CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1607:*:*:*:*:*:*:* | ||
1703CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1703:*:*:*:*:*:*:* | ||
1709CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1709:*:*:*:*:*:*:* | ||
1803CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10:1803:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Vulnerability for Windows Remote Desktop Services (RDP) Remote Code Execution
Sep 3, 2019Vulnerability for Windows Remote Desktop Services (RDP) Remote Code Execution
Sep 3, 2019Vulnerability for Windows Remote Desktop Services (RDP) Remote Code Execution
Sep 3, 2019Vulnerability for Windows Remote Desktop Services (RDP) Remote Code Execution
Sep 3, 2019Vulnerability for Windows Remote Desktop Services (RDP) Remote Code Execution
Sep 3, 2019Remote Desktop Services Remote Code Execution Vulnerability
Aug 13, 2019