PatchSiren

PatchSiren cyber security CVE debrief

CVE-2019-0708 Microsoft CVE debrief

CVE-2019-0708 affects Microsoft Remote Desktop Services and is described as a remote code execution vulnerability. CISA includes it in the Known Exploited Vulnerabilities catalog and notes known ransomware campaign use, so it should be treated as a high-priority remediation item. The official guidance in the KEV record is to apply updates per vendor instructions.

Vendor
Microsoft
Product
Remote Desktop Services
CVSS
CRITICAL 9.8
CISA KEV
Listed
Original CVE published
2021-11-03
Original CVE updated
2021-11-03
Advisory published
2021-11-03
Advisory updated
2021-11-03

Who should care

Security teams, Windows administrators, endpoint and infrastructure owners, and incident responders responsible for systems exposing Microsoft Remote Desktop Services.

Technical summary

The available official records identify this as a Microsoft Remote Desktop Services remote code execution issue. CISA’s KEV entry marks it as known exploited and associates it with known ransomware campaign use. The KEV remediation note is to apply vendor updates.

Defensive priority

High. This is a known exploited vulnerability in CISA KEV, which typically warrants prompt patching and exposure review across all affected systems.

Recommended defensive actions

  • Apply Microsoft updates per vendor instructions as referenced by CISA KEV.
  • Inventory systems running or exposing Microsoft Remote Desktop Services.
  • Prioritize patching and remediation for internet-facing or business-critical hosts first.
  • Review remote access pathways and reduce unnecessary exposure where possible.
  • Confirm that vulnerable systems are included in vulnerability management and patch verification workflows.

Evidence notes

All statements are limited to the supplied official corpus: CISA KEV lists the vulnerability as Microsoft Remote Desktop Services Remote Code Execution Vulnerability, marks known ransomware campaign use as "Known," and directs defenders to apply updates per vendor instructions. The resource links provided are the official CVE record, NVD detail page, CISA KEV catalog, and the source KEV JSON feed.

Sources and references

Verified primary and authoritative sources

  • CVE-2019-0708 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2019-0708

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2019-0708 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2019-0708

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.