CVE-2019-0708
KEV RANSOMWAREHIGH 10.0EPSS 100.0%
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 100.00% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2021-11-03, used in ransomware campaigns
- Published
- 2019-05-16
- Updated
- 2025-10-21
Proof-of-concept exploits (136)
- http://packetstormsecurity.com/files/153133/Microsoft-Windows-Remote-Desktop-BlueKeep-Den…
- http://packetstormsecurity.com/files/153627/Microsoft-Windows-RDP-BlueKeep-Denial-Of-Serv…
- http://packetstormsecurity.com/files/154579/BlueKeep-RDP-Remote-Windows-Kernel-Use-After-…
- http://packetstormsecurity.com/files/162960/Microsoft-RDP-Remote-Code-Execution.html
- 0x4D31/fatt685★ · 2023-10-28
- 0x6b7966/CVE-2019-0708-RCE1★ · 2019-09-07
- 0xFlag/CVE-2019-0708-test1★ · 2019-09-13
- 0xeb-bp/bluekeep293★ · 2019-11-19
- 1aa87148377/CVE-2019-07081★ · 2019-09-17
- 1v4nTR4P/blue0★ · 2022-06-14
- 303sec/CVE-2019-07081★ · 2019-05-17
- AaronCaiii/CVE-2019-0708-POC0★ · 2020-11-06
- AdministratorGithub/CVE-2019-07081★ · 2019-07-09
- Ameg-yag/Wincrash0★ · 2019-10-11
- Barry-McCockiner/CVE-2019-07081★ · 2019-05-16
- CircuitSoul/CVE-2019-07081★ · 2021-06-19
- DeathStroke-source/Mass-scanner-for-CVE-2019-0708-RDP-RCE-Exploit1★ · 2019-05-22
- Ekultek/BlueKeep1183★ · 2026-03-16
- FrostsaberX/CVE-2019-07084★ · 2019-09-07
- FroydCod3r/CVE-2019-07081★ · 2021-06-19
- GryllsAaron/CVE-2019-0708-POC0★ · 2020-11-06
- H4ck3rKing/Vulnerability-Assessment-and-Pentesting-VAPT-on-Windows-73★ · 2024-06-24
- HackerJ0e/CVE-2019-07081★ · 2019-05-15
- Jaky5155/cve-2019-0708-exp30★ · 2019-05-22
- JasonLOU/CVE-2019-07081★ · 2019-05-31
- Leoid/CVE-2019-0708127★ · 2019-05-28
- LuisMfragoso/pentesttoolsframework-10★ · 2023-05-30
- NAXG/cve_2019_0708_bluekeep_rce128★ · 2021-04-18
- NullByteSuiteDevs/CVE-2019-07086★ · 2019-05-15
- Pa55w0rd/CVE-2019-070813★ · 2021-03-31
- Pamenarti/bluekeep-rfe-rce0★ · 2025-03-26
- RICSecLab/CVE-2019-0708148★ · 2022-03-28
- Ravaan21/Bluekeep-Hunter4★ · 2023-03-12
- RickGeex/msf-module-CVE-2019-070813★ · 2019-09-07
- Royalboy2000/codeRDPbreaker1★ · 2023-08-05
- SQLDebugger/CVE-2019-0708-Tool0★ · 2019-05-31
- Sayeedh784/Windows-Exploitation-by-RDP0★ · 2025-02-08
- ShadowBrokers-ExploitLeak/CVE-2019-07082★ · 2019-05-16
- SherlockSec/CVE-2019-070813★ · 2019-05-14
- TinToSer/bluekeep-exploit106★ · 2019-09-24
- UraSecTeam/CVE-2019-07081★ · 2019-05-30
- VarshiniRM/Windows-Exploitation-0★ · 2025-05-10
- YHZX2013/CVE-2019-07092★ · 2019-05-30
- YSheldon/MS_T1201★ · 2019-05-15
- ZhaoYukai/CVE-2019-07080★ · 2019-05-31
- ZhaoYukai/CVE-2019-0708-Batch-Blue-Screen0★ · 2019-06-06
- adi928/brocata6★ · 2019-07-23
- adyanamul/Remote-Code-Execution-RCE-Exploit-BlueKeep-CVE-2019-0708-PoC1★ · 2024-06-02
- algo7/bluekeep_CVE-2019-0708_poc_to_exploit342★ · 2021-01-10
- andreafioraldi/cve_searchsploit177★ · 2022-11-16
- andripwn/CVE-2019-07083★ · 2020-09-20
- anquanscan/CVE-2019-07089★ · 2019-05-15
- areusecure/CVE-2019-07083★ · 2019-05-15
- biggerwing/CVE-2019-0708-poc82★ · 2019-05-30
- blacksunwen/CVE-2019-070819★ · 2019-05-29
- blockchainguard/CVE-2019-07085★ · 2019-05-23
- cbwang505/CVE-2019-0708-EXP-Windows317★ · 2020-01-21
- closethe/CVE-2019-0708-POC13★ · 2019-05-24
- coolboy4me/cve-2019-0708_bluekeep_rce75★ · 2019-09-30
- cream-sec/CVE-2019-0708-Msf--1★ · 2019-06-12
- cve-2019-0708-poc/cve-2019-070818★ · 2019-07-18
- cvencoder/cve-2019-070814★ · 2019-06-24
- distance-vector/CVE-2019-07081★ · 2019-09-11
- dorkerdevil/Remote-Desktop-Services-Remote-Code-Execution-Vulnerability-CVE-2019-0708-122★ · 2019-08-19
- eastmountyxz/CVE-2019-0708-Windows5★ · 2020-03-13
- edvacco/CVE-2019-0708-POC2★ · 2019-05-21
- f8al/CVE-2019-0708-POC0★ · 2019-05-28
- freeide/CVE-2019-07081★ · 2019-05-15
- freeide/CVE-2019-0708-PoC-Exploit0★ · 2019-05-23
- ga1ois/BlueHat-2019-Seattle69★ · 2019-12-02
- gildaaa/CVE-2019-07081★ · 2019-05-15
- gobysec/CVE-2019-070817★ · 2019-05-23
- haishanzheng/CVE-2019-0708-generate-hosts2★ · 2019-05-29
- hawk-520/CVE-2019-07083★ · 2019-05-22
- herhe/CVE-2019-0708poc1★ · 2019-05-27
- hook-s3c/CVE-2019-0708-poc47★ · 2019-05-15
- hotdog777714/RDS_CVE-2019-07081★ · 2019-05-15
- ht0Ruial/CVE-2019-0708Poc-BatchScanning5★ · 2019-05-28
- hwiewie/IS0★ · 2023-08-09
- infenet/CVE-2019-07082★ · 2019-05-15
- infiniti-team/CVE-2019-07086★ · 2019-05-29
- isabelacostaz/CVE-2019-0708-POC0★ · 2025-04-30
- jiansiting/CVE-2019-070819★ · 2019-06-01
- k8gege/CVE-2019-0708388★ · 2019-06-13
- lp008/CVE_2019_0708_Blue_screen_poc1★ · 2019-05-31
- matengfei000/CVE-2019-07089★ · 2019-05-15
- mekhalleh/cve-2019-070823★ · 2019-10-01
- n0auth/CVE-2019-070811★ · 2019-05-15
- n1xbyte/CVE-2019-0708496★ · 2019-06-01
- namtran1151997/cev-1181-an-ninh-mang0★ · 2026-03-16
- nochemax/bLuEkEeP-GUI1★ · 2020-05-23
- ntkernel0/CVE-2019-07081★ · 2019-07-25
- odimarf/blekeep0★ · 2026-03-16
- offensity/CVE-2019-07080★ · 2021-12-20
- oneoy/BlueKeep0★ · 2019-05-29
- p0p0p0/CVE-2019-0708-exploit121★ · 2019-05-15
- pry0cc/cve-2019-0708-23★ · 2019-05-15
- pywc/CVE-2019-07080★ · 2021-08-04
- qing-root/CVE-2019-0708-EXP-MSF-11★ · 2019-09-07
- qq431169079/CVE-2019-07092★ · 2019-05-26
- rasan2001/CVE-2019-07080★ · 2024-05-10
- rasan2001/Microsoft-Remote-Desktop-Services-Remote-Code-Execution-Vulnerability-CVE-2019-…0★ · 2024-05-10
- reg123reg/unKnown0★ · 2020-11-04
- rockmelodies/CVE-2019-0708-Exploit31★ · 2019-05-15
- safly/CVE-2019-07081★ · 2019-05-16
- sbkcbig/CVE-2019-0708-EXPloit1★ · 2019-05-15
- sbkcbig/CVE-2019-0708-EXPloit-33890★ · 2019-05-15
- skommando/CVE-2019-07082★ · 2019-09-12
- skyshell20082008/CVE-2019-0708-PoC-Hitting-Path12★ · 2019-05-19
- smallFunction/CVE-2019-0708-POC2★ · 2019-05-23
- soyluisdev/pentesttoolsframework-10★ · 2023-05-30
- syriusbughunt/CVE-2019-070839★ · 2019-05-16
- temp-user-2014/CVE-2019-07081★ · 2019-05-15
- thugcrowd/CVE-2019-07087★ · 2019-08-28
- tinhtrumtd/ANM_CVE_2019_07080★ · 2022-11-22
- ttsite/CVE-2019-07081★ · 2019-07-04
- ttsite/CVE-2019-0708-2★ · 2019-06-11
- turingcompl33t/bluekeep4★ · 2019-11-04
- uk45/XploitHunt0★ · 2019-12-26
- ulisesrc/-2-CVE-2019-07081★ · 2019-11-22
- ulisesrc/BlueKeep0★ · 2026-03-16
- umarfarook882/CVE-2019-070840★ · 2020-06-14
- victor0013/CVE-2019-07083★ · 2019-05-22
- wdfcc/CVE-2019-07081★ · 2019-06-20
- welove88888/8880★ · 2019-05-25
- worawit/CVE-2019-0708109★ · 2020-07-07
- wqsemc/CVE-2019-070812★ · 2019-09-16
- ycdxsb/PocOrExp_in_Github1197★ · 2026-08-30
- yetiddbb/CVE-2019-0708-PoC0★ · 2019-05-15
- yushiro/CVE-2019-07081★ · 2019-05-17
- ze0r/CVE-2019-0708-exp12★ · 2019-07-25
- zerosum0x0-archive/archive60★ · 2021-12-21
- zjw88282740/CVE-2019-0708-win71★ · 2019-05-21
- SebasPV27/Explotacion-RCE-Pentesting-BlueKeep-CVE-2019-0708-
- benhe119/bluekeepscan
- zoujialan/CVE-2019-0708-RCE
Metasploit modules (1)
ExploitDB entries (4)
- https://www.exploit-db.com/exploits/47416
- https://www.exploit-db.com/exploits/47683
- https://www.exploit-db.com/exploits/47120
- https://www.exploit-db.com/exploits/46946