CVE-2019-0708 KEV EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-03.
Description
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 100% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-416 |
| On CISA KEV | yes — remediate by 2022-05-03 |
| Public exploit | yes |
| Published | 2019-05-16 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Microsoft Remote Desktop Services Remote Code Execution Vulnerability |
|---|---|
| Added | 2021-11-03 |
| Due | 2022-05-03 |
| Vendor / product | Microsoft / Remote Desktop Services |
| Ransomware use | known |
Affected (40)
| Vendor | Product |
|---|---|
| microsoft | windows 7 |
| microsoft | windows server 2008 |
| siemens | aptio |
| siemens | aptio firmware |
| siemens | atellica solution |
| siemens | atellica solution firmware |
| siemens | axiom multix m |
| siemens | axiom multix m firmware |
| siemens | axiom vertix md trauma |
| siemens | axiom vertix md trauma firmware |
| siemens | axiom vertix solitaire m |
| siemens | axiom vertix solitaire m firmware |
| siemens | centralink |
| siemens | centralink firmware |
| siemens | mobilett xp digital |
| siemens | mobilett xp digital firmware |
| siemens | multix pro |
| siemens | multix pro acss |
| siemens | multix pro acss firmware |
| siemens | multix pro acss p |
| siemens | multix pro acss p firmware |
| siemens | multix pro firmware |
| siemens | multix pro navy |
| siemens | multix pro navy firmware |
| siemens | multix pro p |
| siemens | multix pro p firmware |
| siemens | multix swing |
| siemens | multix swing firmware |
| siemens | multix top |
| siemens | multix top acss |
| siemens | multix top acss firmware |
| siemens | multix top acss p |
| siemens | multix top acss p firmware |
| siemens | multix top firmware |
| siemens | multix top p |
| siemens | multix top p firmware |
| siemens | streamlab |
| siemens | streamlab firmware |
| siemens | vertix solitaire |
| siemens | vertix solitaire firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Windows 7 (x86) - 'BlueKeep' Remote Desktop Protocol (RDP) Remote Windows Kernel Use After Free | 2019-11-19 |
| exploit-db | Microsoft Windows - BlueKeep RDP Remote Windows Kernel Use After Free (Metasploit) | 2019-09-24 |
| exploit-db | Microsoft Windows Remote Desktop - 'BlueKeep' Denial of Service (Metasploit) | 2019-07-15 |
| exploit-db | Microsoft Windows Remote Desktop - 'BlueKeep' Denial of Service | 2019-05-30 |
References
- http://packetstormsecurity.com/files/153133/Microsoft-Windows-Remote-Desktop-BlueKeep-Denial-Of-Service.html
- http://packetstormsecurity.com/files/153627/Microsoft-Windows-RDP-BlueKeep-Denial-Of-Service.html
- http://packetstormsecurity.com/files/154579/BlueKeep-RDP-Remote-Windows-Kernel-Use-After-Free.html
- http://packetstormsecurity.com/files/155389/Microsoft-Windows-7-x86-BlueKeep-RDP-Use-After-Free.html
- http://packetstormsecurity.com/files/162960/Microsoft-RDP-Remote-Code-Execution.html
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190529-01-windows-en
- http://www.huawei.com/en/psirt/security-notices/huawei-sn-20190515-01-windows-en
- https://cert-portal.siemens.com/productcert/pdf/ssa-166360.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-406175.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-433987.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-616199.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-832947.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-932041.pdf
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708
- http://packetstormsecurity.com/files/153133/Microsoft-Windows-Remote-Desktop-BlueKeep-Denial-Of-Service.html
- http://packetstormsecurity.com/files/153627/Microsoft-Windows-RDP-BlueKeep-Denial-Of-Service.html
- http://packetstormsecurity.com/files/154579/BlueKeep-RDP-Remote-Windows-Kernel-Use-After-Free.html
- http://packetstormsecurity.com/files/155389/Microsoft-Windows-7-x86-BlueKeep-RDP-Use-After-Free.html
- http://packetstormsecurity.com/files/162960/Microsoft-RDP-Remote-Code-Execution.html
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190529-01-windows-en
→ the Explorer · watch your stack · NVD