PatchSiren cyber security CVE debrief
CVE-2019-0708 Microsoft CVE debrief
CVE-2019-0708 affects Microsoft Remote Desktop Services and is described as a remote code execution vulnerability. CISA includes it in the Known Exploited Vulnerabilities catalog and notes known ransomware campaign use, so it should be treated as a high-priority remediation item. The official guidance in the KEV record is to apply updates per vendor instructions.
- Vendor
- Microsoft
- Product
- Remote Desktop Services
- CVSS
- CRITICAL 9.8
- CISA KEV
- Listed
- Original CVE published
- 2021-11-03
- Original CVE updated
- 2021-11-03
- Advisory published
- 2021-11-03
- Advisory updated
- 2021-11-03
Who should care
Security teams, Windows administrators, endpoint and infrastructure owners, and incident responders responsible for systems exposing Microsoft Remote Desktop Services.
Technical summary
The available official records identify this as a Microsoft Remote Desktop Services remote code execution issue. CISA’s KEV entry marks it as known exploited and associates it with known ransomware campaign use. The KEV remediation note is to apply vendor updates.
Defensive priority
High. This is a known exploited vulnerability in CISA KEV, which typically warrants prompt patching and exposure review across all affected systems.
Recommended defensive actions
- Apply Microsoft updates per vendor instructions as referenced by CISA KEV.
- Inventory systems running or exposing Microsoft Remote Desktop Services.
- Prioritize patching and remediation for internet-facing or business-critical hosts first.
- Review remote access pathways and reduce unnecessary exposure where possible.
- Confirm that vulnerable systems are included in vulnerability management and patch verification workflows.
Evidence notes
All statements are limited to the supplied official corpus: CISA KEV lists the vulnerability as Microsoft Remote Desktop Services Remote Code Execution Vulnerability, marks known ransomware campaign use as "Known," and directs defenders to apply updates per vendor instructions. The resource links provided are the official CVE record, NVD detail page, CISA KEV catalog, and the source KEV JSON feed.
Sources and references
Verified primary and authoritative sources
-
CVE-2019-0708 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2019-0708
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2019-0708 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-0708
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.