ZeroHour

CVE-2019-0708

KEV ransomware PoC ×4mass

Unauthenticated RCE in Microsoft Remote Desktop Services (BlueKeep)

CISA: Microsoft Remote Desktop Services Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

CVE-2019-0708 is a use-after-free (CWE-416) vulnerability in Microsoft Remote Desktop Services, formerly Terminal Services, in which an unauthenticated attacker can connect to a target system over RDP and send specially crafted requests to trigger the flaw. Because the trigger requires no authentication, the flaw is wormable: a successful exploit grants remote code execution on the target host, potentially with elevated privileges, and could allow self-propagating attacks similar to WannaCry. Organizations running the affected Microsoft Remote Desktop Services, particularly legacy Windows releases still accepting inbound RDP connections, are in scope. Exploitation is confirmed in the wild: the flaw (nicknamed BlueKeep) is listed in CISA's KEV catalog (added 2021-11-03), CISA notes known ransomware use, and EPSS assigns it a 100% probability of exploitation within 30 days.

What to do: Apply Microsoft's security updates for CVE-2019-0708 per vendor instructions, prioritizing legacy or end-of-support Windows systems exposed to inbound RDP. As mitigation, restrict RDP (TCP 3389) to trusted networks or VPN access, require Network Level Authentication (NLA), and audit perimeter firewalls and public scans for open RDP listeners. The vulnerability is in the CISA KEV catalog, so patching is treated as a required action for federal and high-risk environments.

Affected
Microsoft Remote Desktop Services
Estimated exposure
masson the order of millions of internet-exposed RDP endpoints and far more internal systems — Public internet-wide scans of open RDP (TCP 3389) have repeatedly shown millions of exposed endpoints, and the enormous installed base of legacy Windows systems with Remote Desktop Services enabled makes this a mass-scale exposure.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

CISA Known Exploited Vulnerability
Affected
Microsoft Remote Desktop Services
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
microsoftsiemenshuawei
Products
windows 7, windows server 2008, axiom multix m firmware, axiom vertix md trauma firmware, axiom vertix solitaire m firmware, mobilett xp digital firmware, multix pro acss p firmware, multix pro p firmware, multix pro firmware, multix pro acss firmware, multix pro navy firmware, multix swing firmware
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news