CVE-2019-0708

Microsoft Remote Desktop Services: Remote Code Execution

As of , CVE-2019-0708 in Microsoft Remote Desktop Services is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 3 November 2021
US federal deadline
3 May 2022181 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
KnownCISA changed it from Unknown to Known on 18 July 2025.
EPSS score
0.99Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
Not availableCISA listed it before 4 February 2022, where the EPSS files we read begin.
Public exploit
2 Metasploit modules and 4 Exploit-DB entries (1 verified)
Fix
No vendor link in CISA's entry

What CISA says to do

Apply updates per vendor instructions.

CISA's required action

What the flaw is

Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.

CISA's description

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

The CVE record's description, from microsoft

CVE published
16 May 2019
Assigned by
microsoft
CVSS
9.8 Critical (CVSS 3.1, from CISA-ADP)
CWE-416
Use After Free
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. Exploit-DB published an exploit (EDB-ID 46946).
  3. Exploit-DB published an exploit (EDB-ID 47120).
  4. Exploit-DB published an exploit (EDB-ID 47416).
  5. Exploit-DB published an exploit (EDB-ID 47683).
  6. CISA added it to its list of exploited vulnerabilities.
  7. The US federal deadline to fix it.
  8. CISA changed its entry. Ransomware use: Unknown to Known.

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

Read further