Microsoft Windows is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the affected application. Failed attacks will cause denial-of-service conditions.
Information
Microsoft Windows Server 2008 R2 for x64-based Systems SP1
Microsoft Windows Server 2008 R2 for Itanium-based Systems SP1
Microsoft Windows Server 2008 for x64-based Systems SP2
Microsoft Windows Server 2008 for Itanium-based Systems SP2
Microsoft Windows Server 2008 for 32-bit Systems SP2
Microsoft Windows Server 2003 0
Microsoft Windows 7 for x64-based Systems SP1
Microsoft Windows 7 for 32-bit Systems SP1
Exploit
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
References:
- Proof of concept for CVE-2019-0708 (Github)
- Microsoft Homepage (Microsoft)
- Microsoft Windows Homepage (Microsoft )
- CVE-2019-0708 | Remote Desktop Services Remote Code Execution Vulnerability (Microsoft)
- Prevent a worm by updating Remote Desktop Services (CVE-2019-0708) (Microsoft)