CVE-2019-1222: Microsoft Windows 10
Critical severity, CVSS 9.8. EPSS: 7.6% chance of exploitation in the next 30 days.
A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authentication and requires no user interaction. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit this vulnerability, an attacker would need to send a specially crafted request to the target systems Remote Desktop Service via RDP. The update addresses the vulnerability by correcting how Remote Desktop Services handles connection requests.
Affected products
- Microsoft Windows 10: version 1803 only; version 1809 only; version 1903 only
- Microsoft Windows Server 2016: version 1803 only; version 1903 only
- Microsoft Windows Server 2019: affected versions not specified
Published 2019-08-14. Last modified 2026-06-17.