CVE-2019-0708 Remote Desktop Services Remote Code Execution Vulnerability - Expected Signature

Reply
L1 Bithead

CVE-2019-0708 Remote Desktop Services Remote Code Execution Vulnerability - Expected Signature

Hi,

just wondering on expected release for signature for this Vulnerability?

 

CVE-2019-0708  - Remote Desktop Services Remote Code Execution Vulnerability

 

Details here:

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708

 

regards

 

Paul

L0 Member

Re: CVE-2019-0708 Remote Desktop Services Remote Code Execution Vulnerability - Expected Signature

Hi Guys,

 

Any idea, by when we have signatures for this CVE ?

CVE-2019-0708


@Paul_Stinson wrote:

Hi,

just wondering on expected release for signature for this Vulnerability?

 

CVE-2019-0708  - Remote Desktop Services Remote Code Execution Vulnerability

 

Details here:

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708

 

regards

 

Paul


 

Highlighted
L1 Bithead

Re: CVE-2019-0708 Remote Desktop Services Remote Code Execution Vulnerability - Expected Signature

hey,

got an response from TAC:

 

Regarding Microsoft CVE-2019-0708, PA has investigated a feasibility of network-based vulnerability signature coverage and so far there is no known exploitation of this CVE to possibly create a coverage signature at this time. PA will continue observe should there is any change with regards to this CVE. As per Microsoft advisory a software update fix is currently available for any impacted version of Windows.

May the Force be with You!
L1 Bithead

Re: CVE-2019-0708 Remote Desktop Services Remote Code Execution Vulnerability - Expected Signature

Cheers thanks for the update.....interesting that there is a patch to patch the vulnerability but a signature can't be created for the vulnerability! ;)

L0 Member

Re: CVE-2019-0708 Remote Desktop Services Remote Code Execution Vulnerability - Expected Signature

Is Palo Alto at least looking into creating a signature?  TippingPoint has one and Cisco Talos is looking into creating a Snort rule.

L1 Bithead

Re: CVE-2019-0708 Remote Desktop Services Remote Code Execution Vulnerability - Expected Signature

Snort sigs are live for this as of last night -

 

https://blog.snort.org/2019/05/snort-rule-update-for-may-20-2019.html

L0 Member

Re: CVE-2019-0708 Remote Desktop Services Remote Code Execution Vulnerability - Expected Signature

The signatures dont specifically detect CVE-2019-0708 they were developed to help identify "emerging threats"

 

I have just been informed that Palo Alto's Threat team has a working PoC and are developing a signature. 

L1 Bithead

Re: CVE-2019-0708 Remote Desktop Services Remote Code Execution Vulnerability - Expected Signature

Cisco and Checkpoint both have prevent signatures live right now. PAN is in field POC testing from what I am told and the signature should be GA here in a day or two. 

L0 Member

Re: CVE-2019-0708 Remote Desktop Services Remote Code Execution Vulnerability - Expected Signature

Released in content 8154.
L1 Bithead

Re: CVE-2019-0708 Remote Desktop Services Remote Code Execution Vulnerability - Expected Signature

 

TAC only Link?

 

2019-05-22 09_54_11-Live Community - Access Denied - Live Community.pngDenied!

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!