PoC Index

CVE-2019-0708

KEV RANSOMWAREHIGH 10.0EPSS 100.0%

A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
100.00% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2021-11-03, used in ransomware campaigns
Published
2019-05-16
Updated
2025-10-21

Proof-of-concept exploits (136)

Metasploit modules (1)

ExploitDB entries (4)

Exploit collections (1)

References

Related