Health Canada — Medical Devices · Canada · 2020-03-06 · Type II
🏛Compiled from an official source — the facts on this page are reproduced from the issuing authority’s own published notice, which is linked above. No AI-generated text appears on this page. How we use AI →
Reported risk: On May 14, 2019, Microsoft released a patch for a critical Remote Code Execution vulnerability in Remote Desktop Services (CVE-2019-0708). This vulnerability can be exploited remotely without authentication on systems that use Remote Desktop Services for Windows XP, Windows 7, Windows Server 2003 and Windows Server 2008 operating systems. . An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system. An attacker could then install programs, view, change, or delete data, or create new Windows accounts with full user rights. (creating windows accounts may not give access to data via the Remisol Advance as Remisol Advance users and Windows users are different). If the vulnerability could be exploited locally (which has not been observed so far), in the worst case, it would lock down the computer and ask for a ransom. Therefore a delayed result can be foreseen.
Verify each fact at the issuing agency before acting. Recall scope, affected lots, and remediation instructions may be updated by the agency after our last sync.
ProductGuru indexes recall and safety-alert records from ~30 public agency registries. We are not lawyers, regulators or product-safety consultants. This page restates what the named agency published; consult the primary source above (or qualified counsel in your jurisdiction) before any commercial, medical or safety decision.