Vulnerability intelligence
CVE-2019-0708
Microsoft Remote Desktop Services Remote Code Execution Vulnerability
Microsoft Remote Desktop Services
Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.
CVSS Score
9.8
Critical
EPSS — Exploit Probability
—
Awaiting FIRST.org data
Exploitation
Confirmed in the wild
Used in ransomware campaigns
Remediation
unknown
Federal deadline 2022-05-03
CISA required action
Apply updates per vendor instructions. Deadline for federal agencies: 2022-05-03.
1 article across 1 outlet · first covered Sep 16, 2026 · latest Sep 16, 2026
Associated threat actors
Coverage timeline
-
NightEagle Hackers Hide Exchange Backdoor Behind Stolen VPN Accesssecurelist.com · Sep 16, 2026