CVE-2019-0708
Microsoft Remote Desktop Services Remote Code Execution Vulnerability
9.8
CVSS 3.1
100.0 %
EPSS (current)
2021-11-03
KEV addition
Yes
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: Microsoft / Remote Desktop Services
Published: 2019-05-16 · Due (CISA): 2022-05-03
CWE: CWE-416 · EU list: no
Exploit references (metadata only)
| Source | Reference | Title | Date |
|---|---|---|---|
| metasploit | auxiliary/scanner/rdp/cve_2019_0708_bluekeep | auxiliary/scanner/rdp/cve_2019_0708_bluekeep | 2019-05-14 |
| metasploit | exploit/windows/rdp/cve_2019_0708_bluekeep_rce | exploit/windows/rdp/cve_2019_0708_bluekeep_rce | 2019-05-14 |
| exploitdb | 46946 | Microsoft Windows Remote Desktop - 'BlueKeep' Denial of Service | 2019-05-30 |
| exploitdb | 47120 | Microsoft Windows Remote Desktop - 'BlueKeep' Denial of Service (Metasploit) | 2019-07-15 |
| exploitdb | 47416 | Microsoft Windows - BlueKeep RDP Remote Windows Kernel Use After Free (Metasploit) | 2019-09-24 |
| exploitdb | 47683 | Microsoft Windows 7 (x86) - 'BlueKeep' Remote Desktop Protocol (RDP) Remote Windows Kernel Use After Free | 2019-11-19 |
References only — no downloads or instructions.