CVE-2019-0708
Summary
| CVE | CVE-2019-0708 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-16 19:29:00 UTC |
| Updated | 2021-06-03 18:15:00 UTC |
| Description | A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'. |
Risk And Classification
EPSS: 0.944540000 probability, percentile 0.999920000 (date 2026-04-01)
CISA KEV: Listed on 2021-11-03; due 2022-05-03; ransomware use Known
Problem Types: CWE-416
CISA Known Exploited Vulnerability
| Vendor | Microsoft |
|---|---|
| Product | Remote Desktop Services |
| Name | Microsoft Remote Desktop Services Remote Code Execution Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2019-0708 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Microsoft | Windows 7 | - | sp1 | All | All |
| Operating System | Microsoft | Windows 7 | - | sp1 | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2003 | r2 | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2003 | - | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2003 | r2 | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2008 | - | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2008 | r2 | sp1 | All | All |
| Operating System | Microsoft | Windows Server 2008 | r2 | sp1 | All | All |
| Operating System | Microsoft | Windows Server 2008 | - | sp2 | All | All |
| Operating System | Microsoft | Windows Server 2008 | r2 | sp1 | All | All |
| Operating System | Microsoft | Windows Server 2008 | r2 | sp1 | All | All |
| Operating System | Microsoft | Windows Vista | - | sp2 | All | All |
| Operating System | Microsoft | Windows Vista | - | sp2 | All | All |
| Operating System | Microsoft | Windows Xp | - | sp2 | All | All |
| Operating System | Microsoft | Windows Xp | - | sp3 | All | All |
| Operating System | Microsoft | Windows Xp | - | sp2 | All | All |
| Operating System | Microsoft | Windows Xp | - | sp3 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| BlueKeep RDP Remote Windows Kernel Use-After-Free ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Security Advisory - Remote Code Execution Vulnerability in Some Microsoft Windows Systems | CONFIRM | www.huawei.com | Third Party Advisory |
| Microsoft Windows Remote Desktop BlueKeep Denial Of Service ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708 | MISC | portal.msrc.microsoft.com | Patch, Vendor Advisory |
| Microsoft Windows RDP BlueKeep Denial Of Service ≈ Packet Storm | MISC | packetstormsecurity.com | |
| cert-portal.siemens.com/productcert/pdf/ssa-406175.pdf | CONFIRM | cert-portal.siemens.com | Third Party Advisory |
| cert-portal.siemens.com/productcert/pdf/ssa-616199.pdf | CONFIRM | cert-portal.siemens.com | Third Party Advisory |
| cert-portal.siemens.com/productcert/pdf/ssa-832947.pdf | CONFIRM | cert-portal.siemens.com | Third Party Advisory |
| Microsoft Windows 7 (x86) BlueKeep RDP Use-After-Free ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Microsoft RDP Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| cert-portal.siemens.com/productcert/pdf/ssa-433987.pdf | CONFIRM | cert-portal.siemens.com | Third Party Advisory |
| cert-portal.siemens.com/productcert/pdf/ssa-932041.pdf | CONFIRM | cert-portal.siemens.com | Third Party Advisory |
| Security Notice - Statement on Microsoft Remote Code Execution Vulnerability(CVE-2019-0708) | CONFIRM | www.huawei.com | Third Party Advisory |
| cert-portal.siemens.com/productcert/pdf/ssa-166360.pdf | CONFIRM | cert-portal.siemens.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.