All CVEs
Vulnerability intelligence

CVE-2019-0708

Microsoft Remote Desktop Services Remote Code Execution Vulnerability

Microsoft Remote Desktop Services

Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.

CVSS Score
9.8
Critical
EPSS — Exploit Probability
Awaiting FIRST.org data
Exploitation
Confirmed in the wild
Used in ransomware campaigns
Remediation
unknown
Federal deadline 2022-05-03
CISA required action

Apply updates per vendor instructions. Deadline for federal agencies: 2022-05-03.

NVD entry PoC / advisory CISA KEV

1 article across 1 outlet · first covered Sep 16, 2026 · latest Sep 16, 2026

Associated threat actors

Coverage timeline

Related CVEs — Microsoft