New Search

Remote Desktop Services Remote Code Execution Vulnerability - CVE-2019-0887

oval:org.cisecurity:def:6580

A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an authenticated attacker abuses clipboard redirection. An attacker who successfully exploited this vulnerability could execute arbitrary code on the victim system. An attacker could then install programs; view change or delete data; or create new accounts with full user rights. To exploit this vulnerability an attacker must already have compromised a system running Remote Desktop Services and then wait for a victim system to connect to Remote Desktop Services. The update addresses the vulnerability by correcting how Remote Desktop Services handles clipboard redirection.

Family:
windows
Status:
ACCEPTED
Platform(s):
  • Microsoft Windows Server 2008 R2
  • Microsoft Windows 10
  • Microsoft Windows 7
  • Microsoft Windows Server 2008
  • Microsoft Windows Server 2016
  • Microsoft Windows 8.1
  • Microsoft Windows Server 2019
  • Microsoft Windows Server 2012 R2
  • Microsoft Windows Server 2012
Class:
vulnerability
Reference(s):
  • CVE-2019-0887
  • MSRC-CVE-2019-0887
  • KB4507456
  • KB4507461
  • KB4507464
  • KB4507457
  • KB4507458
  • KB4507460
  • KB4507450
  • KB4507455
  • KB4507435
  • KB4507469
  • KB4507453
Product(s):