Junglewise Threat Intelligence

CVE-2019-0708: Microsoft Remote Desktop Services Remote Code Execution Vulnerability

CVE-2019-0708 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Vendors: Microsoft.

Executive brief

A remote code execution vulnerability, known as BlueKeep, exists in Microsoft Remote Desktop Services (formerly Terminal Services) due to a use-after-free error. An unauthenticated attacker can exploit this by sending specially crafted requests over RDP to the target system, potentially allowing for full system takeover.

Affected products

  • Microsoft Remote Desktop Services (Terminal Services)

Timeline

  • 2019-05-14: advisory: Initial Microsoft security advisory published
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed: Publication date listed in advisory