CVE-2019-0708
CVE-2019-0708
In short
A critical vulnerability in Windows Remote Desktop Services allows attackers to execute malicious code on a computer remotely without needing a password or login credentials. This is dangerous because attackers can take complete control of affected systems over the internet.
Technical detail
A use-after-free vulnerability (CWE-416) in RDP protocol handling permits unauthenticated remote code execution when specially crafted packets are sent to the RDP service. The attack requires network access to port 3389 but no prior authentication or user interaction, enabling wormable exploitation across vulnerable Windows systems.
Summary generated and translated by AI from the official description.
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
public PoCs found — 135
githubgithub.com/Ekultek/BlueKeep★ 1183githubgithub.com/robertdavidgraham/rdpscan★ 920githubgithub.com/n1xbyte/CVE-2019-0708★ 496githubgithub.com/k8gege/CVE-2019-0708★ 389githubgithub.com/algo7/bluekeep_CVE-2019-0708_poc_to_exploit★ 344githubgithub.com/cbwang505/CVE-2019-0708-EXP-Windows★ 318githubgithub.com/0xeb-bp/bluekeep★ 293githubgithub.com/Cyb0r9/ispy★ 243githubgithub.com/RICSecLab/CVE-2019-0708★ 149githubgithub.com/Leoid/CVE-2019-0708★ 127githubgithub.com/dorkerdevil/Remote-Desktop-Services-Remote-Code-Execution-Vulnerability-CVE-2019-0708-★ 122githubgithub.com/p0p0p0/CVE-2019-0708-exploit★ 121githubgithub.com/worawit/CVE-2019-0708★ 110githubgithub.com/biggerwing/CVE-2019-0708-poc★ 82githubgithub.com/coolboy4me/cve-2019-0708_bluekeep_rce★ 75githubgithub.com/hook-s3c/CVE-2019-0708-poc★ 47githubgithub.com/umarfarook882/CVE-2019-0708★ 40githubgithub.com/syriusbughunt/CVE-2019-0708★ 39githubgithub.com/rockmelodies/CVE-2019-0708-Exploit★ 31githubgithub.com/Jaky5155/cve-2019-0708-exp★ 30githubgithub.com/HynekPetrak/detect_bluekeep.py★ 27githubgithub.com/mekhalleh/cve-2019-0708★ 25githubgithub.com/blacksunwen/CVE-2019-0708★ 19githubgithub.com/jiansiting/CVE-2019-0708★ 19githubgithub.com/fourtwizzy/CVE-2019-0708-Check-Device-Patch-Status★ 18githubgithub.com/cve-2019-0708-poc/cve-2019-0708★ 18githubgithub.com/gobysec/CVE-2019-0708★ 17githubgithub.com/cvencoder/cve-2019-0708★ 14githubgithub.com/closethe/CVE-2019-0708-POC★ 13githubgithub.com/RickGeex/msf-module-CVE-2019-0708★ 13githubgithub.com/Pa55w0rd/CVE-2019-0708★ 13githubgithub.com/SherlockSec/CVE-2019-0708★ 13githubgithub.com/ze0r/CVE-2019-0708-exp★ 12githubgithub.com/skyshell20082008/CVE-2019-0708-PoC-Hitting-Path★ 12githubgithub.com/wqsemc/CVE-2019-0708★ 12githubgithub.com/qing-root/CVE-2019-0708-EXP-MSF-★ 11githubgithub.com/n0auth/CVE-2019-0708★ 11githubgithub.com/anquanscan/CVE-2019-0708★ 9githubgithub.com/thugcrowd/CVE-2019-0708★ 7githubgithub.com/SugiB3o/Check-vuln-CVE-2019-0708★ 7githubgithub.com/major203/cve-2019-0708-scan★ 6githubgithub.com/NullByteSuiteDevs/CVE-2019-0708★ 6githubgithub.com/infiniti-team/CVE-2019-0708★ 6githubgithub.com/blockchainguard/CVE-2019-0708★ 5githubgithub.com/ht0Ruial/CVE-2019-0708Poc-BatchScanning★ 5githubgithub.com/eastmountyxz/CVE-2019-0708-Windows★ 5githubgithub.com/turingcompl33t/bluekeep★ 4githubgithub.com/FrostsaberX/CVE-2019-0708★ 4githubgithub.com/pry0cc/BlueKeepTracker★ 4githubgithub.com/Ravaan21/Bluekeep-Hunter★ 4githubgithub.com/areusecure/CVE-2019-0708★ 3githubgithub.com/andripwn/CVE-2019-0708★ 3githubgithub.com/victor0013/CVE-2019-0708★ 3githubgithub.com/pry0cc/cve-2019-0708-2★ 3githubgithub.com/edvacco/CVE-2019-0708-POC★ 2githubgithub.com/infenet/CVE-2019-0708★ 2githubgithub.com/ShadowBrokers-ExploitLeak/CVE-2019-0708★ 2githubgithub.com/ttsite/CVE-2019-0708-★ 2githubgithub.com/smallFunction/CVE-2019-0708-POC★ 2githubgithub.com/haishanzheng/CVE-2019-0708-generate-hosts★ 2githubgithub.com/skommando/CVE-2019-0708★ 2githubgithub.com/zjw88282740/CVE-2019-0708-win7★ 1githubgithub.com/freeide/CVE-2019-0708★ 1githubgithub.com/ttsite/CVE-2019-0708★ 1githubgithub.com/yushiro/CVE-2019-0708★ 1githubgithub.com/UraSecTeam/CVE-2019-0708★ 1githubgithub.com/Gh0st0ne/rdpscan-BlueKeep★ 1githubgithub.com/303sec/CVE-2019-0708★ 1githubgithub.com/JasonLOU/CVE-2019-0708★ 1githubgithub.com/AdministratorGithub/CVE-2019-0708★ 1githubgithub.com/safly/CVE-2019-0708★ 1githubgithub.com/Barry-McCockiner/CVE-2019-0708★ 1githubgithub.com/wdfcc/CVE-2019-0708★ 1githubgithub.com/HackerJ0e/CVE-2019-0708★ 1githubgithub.com/sbkcbig/CVE-2019-0708-Poc-exploit★ 1githubgithub.com/gildaaa/CVE-2019-0708★ 1githubgithub.com/hotdog777714/RDS_CVE-2019-0708★ 1githubgithub.com/ntkernel0/CVE-2019-0708★ 1githubgithub.com/YSheldon/MS_T120★ 1githubgithub.com/sbkcbig/CVE-2019-0708-EXPloit★ 1githubgithub.com/temp-user-2014/CVE-2019-0708★ 1githubgithub.com/0x6b7966/CVE-2019-0708-RCE★ 1githubgithub.com/distance-vector/CVE-2019-0708★ 1githubgithub.com/0xFlag/CVE-2019-0708-test★ 1githubgithub.com/1aa87148377/CVE-2019-0708★ 1githubgithub.com/ulisesrc/-2-CVE-2019-0708★ 1githubgithub.com/cream-sec/CVE-2019-0708-Msf--★ 1githubgithub.com/JSec1337/Scanner-CVE-2019-0708★ 1githubgithub.com/nochemax/bLuEkEeP-GUI★ 1githubgithub.com/DeathStroke-source/Mass-scanner-for-CVE-2019-0708-RDP-RCE-Exploit★ 1githubgithub.com/CircuitSoul/CVE-2019-0708★ 1githubgithub.com/tranqtruong/Detect-BlueKeep★ 1githubgithub.com/adyanamul/Remote-Code-Execution-RCE-Exploit-BlueKeep-CVE-2019-0708-PoC★ 1githubgithub.com/herhe/CVE-2019-0708poc★ 1githubgithub.com/xiyangzuishuai/Dark-Network-CVE-2019-0708★ 0githubgithub.com/yetiddbb/CVE-2019-0708-PoC★ 0githubgithub.com/denuwanjayasekara/CVE-Exploitation-Reports★ 0githubgithub.com/hualy13/CVE-2019-0708-Check★ 0githubgithub.com/isabelacostaz/CVE-2019-0708-POC★ 0githubgithub.com/benhe119/bluekeepscan★ 0githubgithub.com/lisinan988/CVE-2019-0708-scan★ 0githubgithub.com/offensity/CVE-2019-0708★ 0githubgithub.com/davidfortytwo/bluekeep★ 0githubgithub.com/freeide/CVE-2019-0708-PoC-Exploit★ 0githubgithub.com/sbkcbig/CVE-2019-0708-EXPloit-3389★ 0githubgithub.com/gousseine-systems/vuln-rabilit-windows7★ 0githubgithub.com/rasan2001/Microsoft-Remote-Desktop-Services-Remote-Code-Execution-Vulnerability-CVE-2019-0708★ 0githubgithub.com/Micr067/CVE-2019-0708RDP-MSF★ 0githubgithub.com/GopeshKachhadiya/Windows-2★ 0githubgithub.com/CPT-Jack-A-Castle/Haruster-CVE-2019-0708-Exploit★ 0githubgithub.com/SQLDebugger/CVE-2019-0708-Tool★ 0githubgithub.com/Ameg-yag/Wincrash★ 0githubgithub.com/oneoy/BlueKeep★ 0githubgithub.com/f8al/CVE-2019-0708-POC★ 0githubgithub.com/emmadej1234/bluekeep-metasploit-lab-project★ 0githubgithub.com/Ayomide-29/bluekeep_metasploit_practice★ 0githubgithub.com/ayomideadams61-hub/bluekeep-metsploitable-lab★ 0githubgithub.com/AaronCaiii/CVE-2019-0708-POC★ 0githubgithub.com/Nweks/Bluekeep-Metasploit-Lab-Project★ 0githubgithub.com/ryan-ally/rdp0708scanner★ 0githubgithub.com/sezayi1972/CVE-2019-0708★ 0githubgithub.com/zoujialan/CVE-2019-0708-RCE★ 0githubgithub.com/ZhaoYukai/CVE-2019-0708-Batch-Blue-Screen★ 0githubgithub.com/ZhaoYukai/CVE-2019-0708★ 0githubgithub.com/pywc/CVE-2019-0708★ 0githubgithub.com/bibo318/kali-CVE-2019-0708-lab★ 0cve_referencepacketstormsecurity.com/files/162960/Microsoft-RDP-Remote-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/155389/Microsoft-Windows-7-x86-BlueKeep-RDP-Use-After-Free.htmlunverifiedcve_referencepacketstormsecurity.com/files/153133/Microsoft-Windows-Remote-Desktop-BlueKeep-Denial-Of-Service.htmlunverifiedcve_referencepacketstormsecurity.com/files/154579/BlueKeep-RDP-Remote-Windows-Kernel-Use-After-Free.htmlunverifiedexploitdbwww.exploit-db.com/exploits/47416unverifiedexploitdbwww.exploit-db.com/exploits/47120unverifiedexploitdbwww.exploit-db.com/exploits/47683unverifiedcve_referencepacketstormsecurity.com/files/153627/Microsoft-Windows-RDP-BlueKeep-Denial-Of-Service.htmlunverifiedexploitdbwww.exploit-db.com/exploits/46946unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://packetstormsecurity.com/files/153133/Microsoft-Windows-Remote-Desktop-BlueKeep-Denial-Of-Service.htmlhttp://packetstormsecurity.com/files/153627/Microsoft-Windows-RDP-BlueKeep-Denial-Of-Service.htmlhttp://packetstormsecurity.com/files/154579/BlueKeep-RDP-Remote-Windows-Kernel-Use-After-Free.htmlhttp://packetstormsecurity.com/files/155389/Microsoft-Windows-7-x86-BlueKeep-RDP-Use-After-Free.htmlhttp://packetstormsecurity.com/files/162960/Microsoft-RDP-Remote-Code-Execution.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-166360.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-406175.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-433987.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-616199.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-832947.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-932041.pdfhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0708