Microsoft Remote Desktop Services Remote Code Execution Vulnerability
Microsoft — Windows
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
9.8
100.0%
Vector breakdown
- Attack vector
- Network
- Attack complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Published
- May 16, 2019
- Modified
- Jun 17, 2026
- Added to KEV
- Nov 3, 2021
- Federal patch due
- May 3, 2022
CISA required action
Apply updates per vendor instructions.
Weakness classification
Affected packages
Proof-of-concept & exploitation references
8 foundWeaponization
Public repositories whose name or description references CVE-2019-0708, found via a live GitHub search at request time. These are community-sourced signals, not a verified working exploit - cross-check each one before relying on it, and treat higher star counts and recent activity as (weak) corroboration, not proof.
- Ekultek/BlueKeep★ 1182
Proof of concept for CVE-2019-0708
updated Sep 4, 2026
- robertdavidgraham/rdpscan★ 921
A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability.
updated Sep 1, 2026
- n1xbyte/CVE-2019-0708★ 496
dump
updated Sep 1, 2026
- k8gege/CVE-2019-0708★ 388
3389远程桌面代码执行漏洞CVE-2019-0708批量检测工具(Rdpscan Bluekeep Check)
updated Aug 4, 2026
- algo7/bluekeep_CVE-2019-0708_poc_to_exploit★ 342
An Attempt to Port BlueKeep PoC from @Ekultek to actual exploits
updated Jul 29, 2026
- cbwang505/CVE-2019-0708-EXP-Windows★ 317
CVE-2019-0708-EXP-Windows版单文件exe版,运行后直接在当前控制台反弹System权限Shell
updated Aug 4, 2026
- 0xeb-bp/bluekeep★ 293
Public work for CVE-2019-0708
updated Aug 28, 2026
- Cyb0r9/ispy★ 245
ispy V1.0 - Eternalblue(ms17-010)/Bluekeep(CVE-2019-0708) Scanner and exploit ( Metasploit automation )
updated Aug 21, 2026
References
- packetstormsecurity.com
- packetstormsecurity.com
- packetstormsecurity.com
- packetstormsecurity.com
- packetstormsecurity.com
- huawei.com
- huawei.com
- cert-portal.siemens.com
- cert-portal.siemens.com
- cert-portal.siemens.com
- cert-portal.siemens.com
- cert-portal.siemens.com
- cert-portal.siemens.com
- portal.msrc.microsoft.com
- cisa.gov
Frequently asked questions
What is CVE-2019-0708?
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
How severe is CVE-2019-0708?
CVE-2019-0708 has a CVSS base score of 9.8 out of 10 (CVSS 3.1).
Is CVE-2019-0708 actively exploited in the wild?
Yes. CVE-2019-0708 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added Nov 3, 2021, meaning CISA has confirmed evidence of active exploitation. It is also flagged as used in ransomware campaigns.
What is the EPSS score for CVE-2019-0708?
100.0% - meaning FIRST.org's EPSS model estimates a 100.0% probability this vulnerability will be exploited in the wild within 30 days (100% percentile among all scored CVEs).
Is there exploit tooling available for CVE-2019-0708?
We found 8 public GitHub repositories referencing CVE-2019-0708, though none matched a known Nuclei template or Metasploit module at last check. Review each one before relying on it - see the proof-of-concept section above.
What type of vulnerability is CVE-2019-0708?
CVE-2019-0708 is classified under CWE-416 (CWE-416 Use After Free).
Cross-checked against
Impactr finds and proves whether CVE-2019-0708 - or flaws like it - are actually reachable in your own web apps and APIs, with a reproducible exploit as evidence.
Join the waitlist