Forum Discussion
Critical Remote Code Execution Vulnerability CVE-2019-0708...
Our scan currently looks for the installed KB from the windows update, and doesn't include logic to look for the target's NLA configuration.
But! You can use plugin 58453 to see if NLA is enabled or not on your target. Microsoft does state though: "...affected systems are still vulnerable to Remote Code Execution (RCE) exploitation if the attacker has valid credentials that can be used to successfully authenticate. " This is true even if NLA is enabled.
We like to err on the side of caution, and even though NLA being enabled would make exploitation less likely, it doesn't completely mitigate the risk of attack, which is why we still want this plugin to notify customers that are unpatched.
- 7 years ago
Hello Ryan,
Just small clarification required on your comments.Do you mean to say that even after applying KB, Nessus will still show it as unpatched. If possible,could you please provide us the MS KB's to be applied.
- 7 years ago
Ryan can you tell us what KB the plugin 125313 Microsoft RDP RCE (CVE-2019-0708) (uncredentialed check) is looking for?