A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
Published: 2019-11-04
Researchers identify the first in-the-wild exploit of the BlueKeep vulnerability nearly six months after it was disclosed. Background On November 2, security researchers Kevin Beaumont (@GossiTheDog) and Marcus Hutchins (@MalwareTechBlog) confirmed the first in-the-wild exploitation of CVE-2019-0708, also known as BlueKeep.
Published: 2019-08-01
Nearly 80 days after the announcement of BlueKeep, threats of exploitation remain. Those who have not patched remain at risk as rumors of exploit scripts surface.
Published: 2019-07-25
Scanner for “BlueKeep” vulnerability and newly minted exploits for Exim and Jira incorporated into cryptocurrency mining malware.
Published: 2019-05-14
Microsoft has released its May 2019 Security Updates, which includes a fix for BlueKeep (CVE-2019-0708), a critical remote code execution vulnerability affecting the Remote Desktop Service.
https://cert-portal.siemens.com/productcert/pdf/ssa-932041.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-832947.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-616199.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-433987.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-406175.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-166360.pdf
http://www.huawei.com/en/psirt/security-notices/huawei-sn-20190515-01-windows-en
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190529-01-windows-en
http://packetstormsecurity.com/files/155389/Microsoft-Windows-7-x86-BlueKeep-RDP-Use-After-Free.html
https://www.greynoise.io/blog/unmasking-cisas-hidden-kev-ransomware-updates
https://thehackernews.com/2025/04/kimsuky-exploits-bluekeep-rdp.html
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a
https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-215a
https://www.tenable.com/cyber-exposure/a-look-inside-the-ransomware-ecosystem
https://www.tenable.com/cyber-exposure/2020-threat-landscape-retrospective
https://www.tenable.com/blog/from-bugs-to-breaches-25-significant-cves-as-mitre-cve-turns-25
https://www.tenable.com/blog/aa23-215a-2022s-top-routinely-exploited-vulnerabilities
https://www.tenable.com/blog/examining-the-treat-landscape
https://www.tenable.com/blog/how-covid-19-response-is-expanding-the-cyberattack-surface
https://www.tenable.com/blog/tenable-roundup-for-microsoft-s-august-2019-patch-tuesday-dejablue
https://github.com/muhammedalakbarli/cvault
https://github.com/SebasPV27/Explotacion-RCE-Pentesting-BlueKeep-CVE-2019-0708-
https://github.com/chengbochuan3/CVE-Windows-Protocol
https://github.com/CVEasy/cveasy-mcp
https://github.com/26zl/netsec-auditor
https://github.com/enjoylife96962930-a11y/bug-bounty-series-2026
https://github.com/incoquinita/cve_kb_extractor
https://github.com/michaelochoaa/cve-triage-agent
https://github.com/PT-CODING/Netrecon
https://github.com/fayazmohmmand/asm-platform
https://github.com/Hector-Abarca/realrisk-checks
https://github.com/akrishnash/anamoly_detection
https://github.com/harshweb-cyber/Netscout
https://github.com/Guppss/VulnScan-Pro
https://github.com/trishab0807-lgtm/home-network-scanner
https://github.com/tiamat19/NetScan-Pro-SMB
https://github.com/nguyenminhduc3103/CVE_TOOL_SIGMARULE
https://github.com/Silence-Cy/ModuScan
https://github.com/exploitintel/eip-search
https://github.com/Akalka/Ai-Windows-Penetration-testing-Assistant-
https://github.com/ravindranath11818/Windows-pentest-lab
https://github.com/Ernest-Kosmatko/Netrecon
https://github.com/AtharvS7/RiskSense
https://github.com/kkundanI/Network-Security-Scanner
https://github.com/Luca-css/port-scanner-rs
https://github.com/Luca-css/security-api
https://github.com/Arzgui/cve-vulnerability-scanner
https://github.com/s4mjx/Portscanner-py
https://github.com/Nweks/Bluekeep-Metasploit-Lab-Project
https://github.com/ayomideadams61-hub/bluekeep-metsploitable-lab
https://github.com/Ayomide-29/bluekeep_metasploit_practice
https://github.com/emmadej1234/bluekeep-metasploit-lab-project
https://github.com/Chriscoding19/network-vulnerability-scanner
https://github.com/owlsecx/OSpecter
https://github.com/yashtony/network-vulnerability-scanner
https://github.com/chiranths09/Syntecxhub_Project_Vulnerability-CVE-Scanner
https://github.com/abhi12103606/ThreatVision-SOC
https://github.com/lizuyi-6/aetherguard-security-dataset
https://github.com/Gorstak-Zadar/Patcher
https://github.com/nichxlxs/cve-research
https://github.com/Arthurfert/SecLLM-Gen
https://github.com/qrb661r/CVE-MITRE
https://github.com/GopeshKachhadiya/Windows-2
https://github.com/Noxpy/Noxpy
https://github.com/0xMarturano/Noxpy
https://github.com/ThinhNT272/CVE-Analysis
https://github.com/0wn2886/CVE-Web
https://github.com/RicheByte/exploitdbPro
https://github.com/cyberleelawat/LeelawatX-CVE-Hunter
https://github.com/ZTheH/netmap
https://github.com/b4nxzz/CVEs
https://github.com/threatsurfer/cve-attack-mapper
https://github.com/hieubabe123/CVE-Bluekeep
https://github.com/impoliteinte/go-msfdb
https://github.com/thoughtfulroc/go-msfdb
https://github.com/David-Ogrande/CVEs-NVD
https://github.com/kdandy/devtools
https://github.com/hualy13/CVE-2019-0708-Check
https://github.com/DenuwanJayasekara/CVE-Exploitation-Reports
https://github.com/chefphenix25/vuln-rabilit-windows7
https://github.com/tranqtruong/Detect-BlueKeep
https://github.com/davidfortytwo/bluekeep
https://github.com/Ravaan21/Bluekeep-Hunter
https://github.com/CPT-Jack-A-Castle/Haruster-CVE-2019-0708-Exploit
https://github.com/Creamy-Chicken-Soup/writeups-about-analysis-CVEs-and-Exploits-on-the-Windows
https://github.com/5l1v3r1/CVE-2019-0708-DOS
https://github.com/c4dr01d/CVE-2019-0708
https://github.com/FroydCod3r/CVE-2019-0708
https://github.com/matiebarg/CVE-2019-0708
https://github.com/ycdxsb/PocOrExp_in_Github
https://github.com/SurrealSky/CVE20190708SCAN
https://github.com/Haruster/Haruster-CVE-2019-0708-Exploit
https://github.com/nochemax/bLuEkEeP-GUI
https://github.com/JSec1337/Scanner-CVE-2019-0708
https://github.com/eastmountyxz/CSDNBlog-Security-Based
https://github.com/vulsio/go-msfdb
https://github.com/eastmountyxz/CVE-2019-0708-Windows
https://github.com/cbwang505/CVE-2019-0708-EXP-Windows
https://github.com/Ameg-yag/Wincrash
https://github.com/lwtz/CVE-2019-0708
https://github.com/innxrmxst/CVE-2019-0708-DOS
https://github.com/R4v3nG/CVE-2019-0708-DOS
https://github.com/pwnhacker0x18/Wincrash
https://github.com/shishibabyq/CVE-2019-0708
https://github.com/Cyb0r9/ispy
https://github.com/0xFlag/CVE-2019-0708-test
https://github.com/qing-root/CVE-2019-0708-EXP-MSF-
https://github.com/0x6b7966/CVE-2019-0708-RCE
https://github.com/FrostsaberX/CVE-2019-0708
https://github.com/Micr067/CVE-2019-0708RDP-MSF
https://github.com/wqsemc/CVE-2019-0708
https://github.com/RickGeex/msf-module-CVE-2019-0708
https://github.com/TinToSer/bluekeep-exploit
https://github.com/skommando/CVE-2019-0708
https://github.com/cve-2019-0708-poc/cve-2019-0708
https://github.com/at0mik/CVE-2019-0708-PoC
https://github.com/Pa55w0rd/CVE-2019-0708
https://github.com/HynekPetrak/detect_bluekeep.py
https://github.com/AdministratorGithub/CVE-2019-0708
https://github.com/YHZX2013/CVE-2019-0709
https://github.com/Gh0st0ne/rdpscan-BlueKeep
https://github.com/UraSecTeam/CVE-2019-0708
https://github.com/oneoy/BlueKeep
https://github.com/robertdavidgraham/rdpscan
https://github.com/gobysec/CVE-2019-0708
https://github.com/herhe/CVE-2019-0708poc
https://github.com/zerosum0x0/CVE-2019-0708
https://github.com/edvacco/CVE-2019-0708-POC
https://github.com/biggerwing/CVE-2019-0708-poc
https://github.com/haoge8090/CVE-2019-0708
https://github.com/blockchainguard/CVE-2019-0708
https://github.com/fourtwizzy/CVE-2019-0708-Check-Device-Patch-Status
https://github.com/safly/CVE-2019-0708
https://github.com/sbkcbig/CVE-2019-0708-Poc-exploit
https://github.com/blacksunwen/CVE-2019-0708
https://github.com/hotdog777714/RDS_CVE-2019-0708
https://github.com/temp-user-2014/CVE-2019-0708
https://github.com/xiyangzuishuai/Dark-Network-CVE-2019-0708
https://github.com/matengfei000/CVE-2019-0708
https://github.com/anquanscan/CVE-2019-0708
https://github.com/rockmelodies/CVE-2019-0708-Exploit
https://github.com/p0p0p0/CVE-2019-0708-exploit
https://github.com/yetiddbb/CVE-2019-0708-PoC
https://github.com/andreafioraldi/cve_searchsploit
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0708
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708
http://packetstormsecurity.com/files/162960/Microsoft-RDP-Remote-Code-Execution.html
http://packetstormsecurity.com/files/154579/BlueKeep-RDP-Remote-Windows-Kernel-Use-After-Free.html
http://packetstormsecurity.com/files/153627/Microsoft-Windows-RDP-BlueKeep-Denial-Of-Service.html
Published: 2019-05-16
Updated: 2026-06-17
Named Vulnerability: DejaBlueNamed Vulnerability: BlueKeepKnown Exploited Vulnerability (KEV)
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.99999