Potential RDP Exploit CVE-2019-0708

 Original Source: [Sigma source]
Title: Potential RDP Exploit CVE-2019-0708
Status: test
Description:Detect suspicious error on protocol RDP, potential CVE-2019-0708
References:
  -https://web.archive.org/web/20190710034152/https://github.com/zerosum0x0/CVE-2019-0708
  -https://github.com/Ekultek/BlueKeep
Author: Lionel PRAT, Christophe BROCAS, @atc_project (improvements)
Date: 2019-05-24
modified:2022-12-25
Tags:
  • -'attack.lateral-movement'
  • -'attack.t1210'
  • -'car.2013-07-002'
Logsource:
  • product: windows
  • service: system
Detection:
  selection:
    EventID:
      -'56'
      -'50'

    Provider_Name: 'TermDD'
  condition:selection
Falsepositives:
  -Bad connections or network interruptions
Level: medium